WordPress REST API content injection (2017)
A flaw in WordPress's REST API let unauthenticated attackers modify the content of any post or page. It affected every version of WordPress at the time, and the fix required an emergency release.
WordPress rushed out version 4.7.2 within days of disclosure.
The incident showed how a single core flaw can expose every WordPress site simultaneously.
Like CVE-2026-87902, it was a core flaw present in all versions, unauthenticated, and requiring urgent patching across the ecosystem.
