GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain
ID: 905391ff-f52d-5d68-a99e-7929030eaf6d
STIX ID: report--905391ff-f52d-5d68-a99e-7929030eaf6d
Feed Name: Cyber Press
**Critical pre-authentication RCE in WordPress Batch API** — An AI-discovered flaw in the WordPress Batch API allows attackers to desynchronize validation and execution of batched requests, pair that with a sanitization bypass on the author_exclude parameter to perform SQL injection and in-memory post fabrication, elevate privileges by forging a customize_changeset, create an administrator account, and upload a malicious plugin to achieve full code execution; independent reproduction and a scanner have been published and site owners are urged to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
