The hole, which allows an unauthenticated attacker to perform remote code execution, is especially dangerous because many enterprises are not aware of all of their WordPress sites.