I would do a sweep of your code base/DB/servers, you have a breach.
Slightly concerned with the recorded activity I have recoded within your plugin. multiple unauths, and exploits being done via JS scripts through weak access points within your structure on the app