Maybe a bit OTT
"Any orgs that waited until Monday to patch are likely already compromised, Knott warned."
Well running the test against my instance.
"Not vulnerable
The batch API is blocked (likely by a WAF or security plugin), so it cannot be exploited. Keep WordPress up to date regardless."
So it seems that the "already compromised" is hyperbole.