Is this real? Or did they concoct this vulnerability just to write a blog post?

I'm not seeing any mention where they report this to WP or the patch.