The outer class filter worked. Event reconstruction then opened a second object stream beyond that decision. We traced the serialized form, reproduced command execution through the real TCP receiver, and tested the controls.
Research
Security research, from source to proof
Authored investigations into vulnerabilities whose impact only becomes clear when the full state transition is reproduced. Operational details are scoped to responsible public disclosure.
Published investigations
2 articlesThe first proof had an RCE ending but no defensible middle. Rebuilding that middle exposed how request confusion, object caching, partial updates, and nested dispatch could compose across WordPress core.