WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 contain REST API batch route confusion and SQL injection remote code execution vulnerabilities. Unauthenticated remote attackers can exploit these issues to conduct SQL injection and achieve remote code execution. These vulnerabilities pose extremely high risk, and website owners and bloggers are advised to perform self-audits and implement protective measures as soon as possible.
Official WordPress Chinese website: cn.wordpress.org

