{
  "claim_outcome": "confirmed",
  "claim_block_reason": null,
  "repro_result": "confirmed",
  "validated_surface": "api_remote",
  "evidence_scope": "production_path",
  "claimed_impact_class": "code_execution",
  "observed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "Unauthenticated nested JSON requests to stock POST /wp-json/batch/v1 plus attacker-chosen fresh administrator username/password; no owner credential is supplied to the exploit driver.",
  "trigger_path": "REST batch request/handler desynchronization -> shifted posts handler -> scalar author_exclude SQL injection/full-row projection -> oEmbed cache poisoning and partial-update merge -> forged due Customizer changeset -> privileged parse_request REST re-entry -> normal users create handler -> fresh administrator -> wp-login.php -> core plugin uploader -> plugin HTTP command endpoint.",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": false,
  "exploit_chain_demonstrated": true,
  "blocking_mitigation": null,
  "inferred": false
}
