VULNERABILITY in WordPress Core 4.6 – Unauthenticated Remote Code Execution (RCE) PoC Exploit (default configuration, no plugins, no auth) Exploit a vulnerability that could be used by unauthenticated remote attackers to gain instant access to the target server on which a vulnerable WordPress core version was installed in its default configuration. No plugins or non-standard settings are required to exploit the vulnerability. This advisory reveals details of exploitation of the PHPMailer vulnerability (CVE-2016-10033)”]
Source: https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html

