WordPress plugin can be exploited to run PHP commands on the server by posting a comment that contains a malicious payload.
Use this template for a skeleton dev environment for VSCode, Docker, MYSQL and Node.js.