This week's release packs a punch with 5 new modules, including unauthenticated RCEs targeting ChurchCRM and the WordPress StoryChief plugin, plus creative persistence methods for Emacs and Windows. Check it out in the weekly wrap up: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-02-20-2026/
Metasploit Wrap-Up 02/20/2026

Metasploit 6.4.115 brings 5 new modules: unauthenticated RCEs for ChurchCRM (CVE-2025-62521) and WordPress StoryChief (CVE-2025-7441), and creative persistence for Windows & Emacs.

Rapid7