If you are a WordPress site admin, be wary of incoming emails - one could be a phishing message looking to infect your site with malicious plugins. This is the warning given out by WordPress security ...
CleanTalk WordPress plugin vulnerability affecting up to 200,000 sites could lead to remote code execution by unauthenticated attackers.
WPvivid Backup & Migration plugin allows for arbitrary file upload which can lead to remote code execution.