More and more attacks taking advantage of a XSS and RCE bug in the popular plugin have cropped up in the wild.
Source: Threadpost