AI Agent Achieves Full-Chain RCE on WordPress Core Vulnerability
rez0__ · x · 2026-07-19
A developer discovered that their deployed AI Agent successfully identified the final remote code execution (RCE) exploit step for a core WordPress vulnerability.
The PoC referenced by the Agent is named wp2shell, a single-file, zero-dependency proof of concept. Through a single anonymous HTTP request, it chains REST route confusion and unauthenticated SQLi to gain admin privileges, ultimately securing a system shell. This vulnerability affects default WordPress installations and requires no plugins or login.
More from coding & agent
- An MCP server signs every AI agent tool call into a verifiable Merkle chain — Funky_Chicken_22 · 2026-07-22
- Claude Code skill uses 10 Markdown rules to make outputs ADHD-friendly — alex_verem · 2026-07-22
- A Firecracker-based platform says it can host 6,000 AI agents on one 256 GB server — maritime_sh · 2026-07-22
- A better path to agent autonomy is running waves, finding friction, and iterating — JnBrymn · 2026-07-22
- AI agent designers map the visual and tonal cues behind companionship products — Unlikely-Platform-47 · 2026-07-22
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22