The Revive Old Posts – Social Media Auto Post and Scheduling Plugin for WordPress had a security vulnerability that made it possible for unauthenticated attackers to create a new account with the highest level of access. This happened because a certain security check was not in place in versions before 8.0.0, and was only fully fixed when version 8.0.0 removed a certain file called core.php.