wordpress-cors-xmlrpc-rce-chain
Installation
SKILL.md
WordPress CORS, XML-RPC, and Upload Chain
This skill evaluates whether independently verified WordPress behaviors can form a path to unauthorized file execution. It does not assume that CORS, XML-RPC, registration, or an upload method is exploitable merely because it is present.
When to Use
- Credentialed CORS exposes non-public WordPress data.
- XML-RPC returns a protocol-valid method list.
- An approved test identity has an upload-capable role.
- A plugin or core upload operation may accept an executable file.
- The assessment explicitly permits state-changing upload and execution tests.