WordPress exploit chain created an administrator
A novel WP2Shell variant confused WordPress's nested batch handling and used fabricated cached posts to create an administrator. Its unfamiliar payload passed the site's WAF. Aiko removed the account and stopped it from happening again.









