The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.