AI Agent Achieves Full-Chain RCE on WordPress Core Vulnerability

rez0__ · x · 2026-07-19

A developer discovered that their deployed AI Agent successfully identified the final remote code execution (RCE) exploit step for a core WordPress vulnerability.

The PoC referenced by the Agent is named wp2shell, a single-file, zero-dependency proof of concept. Through a single anonymous HTTP request, it chains REST route confusion and unauthenticated SQLi to gain admin privileges, ultimately securing a system shell. This vulnerability affects default WordPress installations and requires no plugins or login.

Original post →

More from coding & agent

coding & agent channel →