A critical pre-authorization remote command execution vulnerability has been found in WordPress. Fortunately, this only impacts versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1. This is fixed in 6.9.5 and 7.0.2. Please be sure to update immediately if you're using an affected version.
More info here: https://wp2shell.com/
More info here: https://wp2shell.com/