WordPress Core has a security issue that allows hackers to remotely execute code using a PHP gadget. This can happen in versions 6.4.0 and 6.4.1 because of a specific method called “__destruct” in the WP_HTML_Token class. This means that if there is also another vulnerability called “deserialization/PHP Object Injection” on the website, attackers can take control and execute their own code.