Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and ...
The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.