The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.Referenceshttps://wpvulndb.com/vulnerabilities/8829https://wordpress.org/plugins/sitebuilder-dynamic-components/#developers