A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site.