Remote File Inclusion (RFI) leading to Remote Code Execution (RCE) via CSRF vulnerability discovered by Krzysztof Zając in WordPress WP Coder plugin (versions <= 2.5.1).
Update the WordPress WP Coder plugin to the latest available version (at least 2.5.2).