Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
Update the WordPress Widget Options Plugin to the latest available version (at least 4.2.4).