Hackers are chaining together two newly discovered flaws to achieve remote code execution.
The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.