How Two WordPress Core Bugs Chained into Pre-Auth RCE
bugbunny.ai | research | #rce | #vulnerability-research | #attack-chains | #rest-api | #sql-injection | #wordpress | #pre-auth | #patching | #vulnerability-chain
Summary
WordPress deep dive: REST batch-route confusion plus a scalar SQL injection, bridged via the object cache, Customizer and nested REST dispatch, formed a pre-auth RCE chain—fixed in 7.0.2, 6.9.5 and 6.8.6.
- Published
- Collected
Skip to content