wp2shell: WordPress patched on Friday, the exploits landed by Sunday. Who maintains your website?
On July 17 WordPress shipped 6.9.5 and 7.0.2 to plug wp2shell, a no-login RCE in core. It was being exploited that same evening, and by Sunday there were more than twenty public exploits. The uncomfortable question isn't technical: who is responsible for updating your website?