WordPress PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a “ (backslash double quote) in a crafted Sender property in isMail transport.
View the template here CVE-2016-10033.yaml
References:
https://www.exploit-db.com/exploits/40970/