GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
ID: 7a33ba32-3f54-5648-933e-d9939b58ce54
STIX ID: report--7a33ba32-3f54-5648-933e-d9939b58ce54
Feed Name: GBHackers
This report describes a critical multi-stage vulnerability chain called "wp2shell" in WordPress's REST Batch API that enables unauthenticated attackers to trigger a pre-auth SQL injection in the posts-listing endpoint, forge WP_Post objects in cache, escalate privileges by creating a temporary administrator account, and ultimately install a malicious plugin to achieve remote code execution; administrators are advised to apply updates, restrict public REST access, review logs for /wp-json/batch/v1 activity, and investigate unexpected admin accounts or plugin installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
