{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "Unauthenticated POST /wp-json/batch/v1 on stock WordPress; successful vulnerable chain then uses normal wp-login.php and core plugin uploader",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "stock wordpress:7.0.1-php8.2-apache at ticket-pinned digest",
    "WordPress 7.0.2 source over the same pinned base image for fixed control",
    "mysql:8.0 at ticket-pinned digest",
    "isolated Python network driver and oEmbed provider"
  ],
  "proof_artifacts": [
    "logs/reproduction_steps.log",
    "logs/source_identity.log",
    "logs/image_identity.log",
    "logs/network_boundary.log",
    "logs/oembed_provider.log",
    "logs/vulnerable_setup.log",
    "logs/vulnerable_database_before.log",
    "logs/vulnerable_http_chain.log",
    "logs/vulnerable_database_after.log",
    "logs/vulnerable_command_response.log",
    "logs/fixed_setup.log",
    "logs/fixed_database_before.log",
    "logs/fixed_http_chain.log",
    "logs/fixed_database_after.log",
    "logs/second_clean_run.log"
  ],
  "notes": "CONFIRMED: two independent clean stock WordPress 7.0.1 targets accepted the unauthenticated REST chain, each created a fresh attacker-chosen administrator, allowed normal login and core plugin upload, and returned a real www-data command marker. On two independent clean WordPress 7.0.2 controls, the unchanged trigger failed before discovering its first disposable oEmbed row; each retained one user and zero oEmbed rows."
}
