Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it.
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until According to The Hacker News, updated july 18, 2026: the two flaws now carry cve ids, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. the story below reflects all of it.
an anonymous http request can run code on a wordpress site. the bug is in core, so a bare install with zero plugins is exploitable. every 6.9 and 7.0 site was in range until. The development comes amid ongoing regulatory scrutiny in the sector. The Hacker News reports that this marks a significant milestone for the industry. The The Hacker News report provides additional context on the implications for market participants and regulatory frameworks moving forward.
