wp2shell: Pre Authentication RCE in WordPress Core
25 points by Helithumper
25 points by Helithumper
Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time.
https://github.com/WordPress/WordPress/compare/7.0.1...7.0.2 https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa60d98bd5a048b603402e70209c
Yeah I don't think it's going to take a genius to reverse engineer this one.
The year is 2026, and apparently we're still building database queries using string formatting ðŸ˜
I was thinking the exact same thing. Many times simply mentioning "there is a vuln within this area" is enough for someone creative to circumvent the "delayed information disclosure", and this one with it's "is this service vuln?" service..
like you my immediate thought was; alright, so find a version that is apparently vuln, find one that isn't.. aaaaand, diff.