正在加载视频...
视频加载失败
🚨 wp2shell : pre-auth RCE in WordPress core, reproduced end-to-end. Nested /batch/v1 "double confusion" · (CVE-2026-63030) → WP_Query SQLi · (CVE-2026-60137) → anonymous shell on a stock install. A couple of prompts later: · Opus 4.8 orchestrating, Sonnet agents executing. Exploit dev has gotten scary easy. Patched in 6.9.5... show more
33,831 次观看 • 2 个月前 •via X (Twitter)
2 条评论

Sandeep Kamble2 个月前
Nah man. You can't easily create RCE with any model. It was not easy.

Aseem Shrey2 个月前
Agreed. I am testing doing it with open source models, like GLM 5.2. This was with sonnet as agents and opus as orchestrator. But also we had the benefit of knowing that there’s a pre-auth RCE in the version change. So you just needed to reverse the patch.
