You Can’t Just Publish Partial Exploits Anymore

Now published over at Xora — a ‘safely’ disclosed WordPress RCE, taken most of the way to a full unauthenticated exploit chain with public research and an LLM, and the rest with a public PoC.

This one ended up over at Xora, so that’s where it lives for now: wp2shell: A Build-Your-Own-Exploit Adventure (opens in new tab).

TL;DR: Hadrian published research on an unauthenticated WordPress RCE and deliberately left the exploit details out, to give administrators time to patch. I wanted to know if withholding still buys anyone time in a post-LLM era. So, I tried building the missing piece of the exploit chain from just the public write-up and the patch diff.

It worked, and the little piece of withheld detail ended up not worth much.

Also published on Substack.