WordPress has patched Click2Shell, that could allow an attacker to silently install a theme and execute PHP code on the targeted website.
A Tutor LMS flaw lets low-privileged users execute code remotely, risking server takeover on 100,000+ WordPress sites.