Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring login details...
7.0.2 got released on Friday. Exploits are already happening. People reporting hacks
Correction: WordPress IS a critical vulnerability.
I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.
Mediocre craftspeople blame their tools.
I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.