Preliminary research
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
A WordPress REST batch mismatch enables nested validation bypass and read-only SQL injection. Forged post objects poison the request cache; oEmbed updates and hierarchy repair persist them as changesets. Temporary administrator authority and a forged hook re-enter REST dispatch to create an admin account, enabling plugin-based RCE.
Record
- Researcher
- Adam Kues
- Published by
- Searchlight Cyber
- Date
In the archive
Related sources
- wp2shell advisory
- Checker and mitigations
- Escalation to root (Calif)
- Calif wp2root code and lab
- Calif technical wp2shell writeup
- Calif full-chain technical writeup
Tags
This page is the archive's own catalogue record. The research is the work of Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host.