Video yükleniyor...
Video Yüklenemedi
🚨 wp2shell : pre-auth RCE in WordPress core, reproduced end-to-end. Nested /batch/v1 "double confusion" · (CVE-2026-63030) → WP_Query SQLi · (CVE-2026-60137) → anonymous shell on a stock install. A couple of prompts later: · Opus 4.8 orchestrating, Sonnet agents executing. Exploit dev has gotten scary easy. Patched in 6.9.5... show more
33,831 görüntüleme • 2 ay önce •via X (Twitter)
2 Yorum

Sandeep Kamble2 ay önce
Nah man. You can't easily create RCE with any model. It was not easy.

Aseem Shrey1 ay önce
Agreed. I am testing doing it with open source models, like GLM 5.2. This was with sonnet as agents and opus as orchestrator. But also we had the benefit of knowing that there’s a pre-auth RCE in the version change. So you just needed to reverse the patch.
