WordPress Critical: RCE flaw mass-exploited within hours
Hours after WordPress released patches for two critical vulnerabilities, attackers began mass-exploiting them. The chain of flaws allows unauthenticated remote code execution (RCE), affecting sites running WordPress 6.9 and 6.8. Tens of thousands of exploitation attempts and hundreds of fraudulent admin accounts have been observed.


