A hidden plugin installed by the attacker acts as a web shell, allowing remote command execution on the compromised server without authentication.
A hidden plugin installed by the attacker acts as a web shell, allowing remote command execution on the compromised server without authentication.