An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited

WordPress runs a large share of the web, which means a flaw in its core is never a small event. On July 17, 2026 the WordPress security team shipped an emergency release to close a pair of vulnerabilities that, used together, let an attacker with no account and no plugin dependency reach a WordPress site’s … Continue reading An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited