Pruva proved the two-CVE chain at runtime: unauthenticated privileged state change, attacker-influenced configuration, then service-context code execution.
Series
Vulnerability research
3 investigations, each built on accepted runtime evidence, captured controls, and an explicit disclosure state. Runnable public proof is linked when coordination permits it.
Entries in this series
3 articlesThe outer class filter worked. Event reconstruction then opened a second object stream beyond that decision. We traced the serialized form, reproduced command execution through the real TCP receiver, and tested the controls.
The first proof had an RCE ending but no defensible middle. Rebuilding that middle exposed how request confusion, object caching, partial updates, and nested dispatch could compose across WordPress core.