A critical flaw in a WordPress plugin used by 90,000 sites is being actively exploited right now, and attackers are getting full remote code execution with a single upload.