Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring login details...
7.0.2 got released on Friday. Exploits are already happening. People reporting hacks
https://www.wordfence.com/threat-intel/vulnerabilities
The CVE list always cracks me up, there’s like tens daily
JFC I thought you were exaggerating.