WordPress secretly fixed critical zero-dayhelpnetsecurity.com
Wordpress has pushed out a fix for a very critical exploit, which allowed anyone to modify any post or page on any Wordpress site. Because of its critical nature, the exploit was kept strictly secret until a fix was available. They did contact sites like Cloudflare and certain Wordpress hosting companies to have them set up protection rules in their web-application firewalls in advance of making the exploit public.
If you do not have automatic updates enabled on your Wordpress installation, make sure to update fast.