The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.
WordPress has issued emergency security updates to block a critical vulnerability that allowed unauthenticated attackers to execute code on websites running standard installations without plugins. The ...