WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
WordPress 6.9 will introduce the Abilities API, which enables the development of advanced AI integrations in WordPress sites.