Pruva proved the two-CVE chain at runtime: unauthenticated privileged state change, attacker-influenced configuration, then service-context code execution.
Research
Security research, from source to proof
Authored investigations into vulnerabilities whose impact only becomes clear when the full state transition is reproduced. Operational details are scoped to responsible public disclosure.
Published investigations
3 articlesThe outer class filter worked. Event reconstruction then opened a second object stream beyond that decision. We traced the serialized form, reproduced command execution through the real TCP receiver, and tested the controls.
The first proof had an RCE ending but no defensible middle. Rebuilding that middle exposed how request confusion, object caching, partial updates, and nested dispatch could compose across WordPress core.