The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.
Millions of websites worldwide, including in Australia, are likely vulnerable to a newly revealed pre-authentication RCE.
By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the ...