This is a republication. The original and always up to date version lives here:
https://own2pwn.fr/articles/appsec/wp2shell-wordpress-rce (it also embeds a live,
non-intrusive exposure checker).
One request. A POST to /wp-json/batch/v1, a slightly twisted JSON body, and the server
answers a perfectly ordinary 200 OK. Thirty seconds later there is one more








