Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How Two WordPress Core Bugs Chained into Pre-Auth RCE

Summary

WordPress deep dive: REST batch-route confusion plus a scalar SQL injection, bridged via the object cache, Customizer and nested REST dispatch, formed a pre-auth RCE chain—fixed in 7.0.2, 6.9.5 and 6.8.6.
Published
Collected

original ↗