Bug Bounty: CORS-to-RCE Chains in WordPress


How a single misconfigured Access-Control-Allow-Origin header escalates into full Remote Code Execution on WordPress sites running vulnerable plugins. A field guide for bug bounty hunters and security researchers.







Introduction


Cross-Origin Resource Sharing (CORS) is a browser security...