This old WordPress plugin is being used to hack websites

Cybersecurity researchers at GoDaddy-owned web security firm Sucuri has found that a legitimate WordPress plugin that’s no longer active has been taken over by hackers and is now compromising websites.

Eval PHP – a plugin designed to allow users to add PHP code into articles and blog data – looks to have been last updated a decade ago and has had minimal to no downloads recorded over the past 10 years.

Source