Multiple critical security vulnerabilities in widely deployed enterprise software are already being actively exploited, often via simple attack vectors such as weak input validation and exposed systems.
The wp2shell core vulnerability in WordPress 6.9 and 7.0 enables code execution through anonymous HTTP requests and has been patched by security updates 6.9.5 and 7.0.2 with forced auto-updates.