Old instances of the popular WordPress Duplicator Plugin are leaving sites open to remote code execution attacks.
Source: Threadpost