Video wird geladen...
Video konnte nicht geladen werden
🚨 wp2shell : pre-auth RCE in WordPress core, reproduced end-to-end. Nested /batch/v1 "double confusion" · (CVE-2026-63030) → WP_Query SQLi · (CVE-2026-60137) → anonymous shell on a stock install. A couple of prompts later: · Opus 4.8 orchestrating, Sonnet agents executing. Exploit dev has gotten scary easy. Patched in 6.9.5... show more
33,831 Aufrufe • vor 2 Monaten •via X (Twitter)
2 Kommentare

Sandeep Kamblevor 2 Monaten
Nah man. You can't easily create RCE with any model. It was not easy.

Aseem Shreyvor 2 Monaten
Agreed. I am testing doing it with open source models, like GLM 5.2. This was with sonnet as agents and opus as orchestrator. But also we had the benefit of knowing that there’s a pre-auth RCE in the version change. So you just needed to reverse the patch.
