wp2shell: A Pre-Auth RCE in WordPress Core With a Day-One Public Exploit
Two chained CVEs in WordPress's REST API batch endpoint let any anonymous request execute code on your server. Patches shipped July 17 — and the PoC hit GitHub the next morning.
Read Article