Ninety Minutes to Weaponized: Inside the WordPress Core RCE Race
A pre-auth SQL injection and a REST batch route confusion in WordPress core were chained into remote code execution. Attackers hit the internet roughly ninety minutes after the fix shipped, and the campaign has not slowed down.