An unauthenticated RCE in WP Compress, patched in 7.20.01
WP Compress ships version 7.20.01 to close a maximum-severity RCE that needs no login. Four other WordPress plugins carry critical bugs the same day, with two PHP object injections, one SQL injection, and one subscriber-level takeover.