WP2Shell: The Pre-Auth RCE Hiding in the Gap Between Two WordPress CVEs
WordPress shipped an emergency fix for two CVEs: a 7.5 route-confusion bug and a 9.1 SQL injection. Apart, both look manageable. Chained, they're a pre-auth RCE on a default install, no login needed. WP2Shell shows why one-CVE-at-a-time triage misses the ones that matter most.