The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
https://wpscan.com/vulnerability/40bd880e-67a1-4180-b197-8dcadaa0ace4/