WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable code execution.
Critical WordPress core flaw discovered: attackers can run code without authentication, putting millions of sites at risk.