wordpress-cors-xmlrpc-rce-chain
Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path.
Install / Use
npx skills add uphiago/recon-skills --skill wordpress-cors-xmlrpc-rce-chainInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Tags
Our assessment of wordpress-cors-xmlrpc-rce-chain
wordpress-cors-xmlrpc-rce-chain scores 84/100 on our quality scale, 686th of 971 Security skills we index.
Its SKILL.md is 5.3 KB long, well organised into 13 sections with 3 code examples: a solid amount of guidance for an agent.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so wordpress-cors-xmlrpc-rce-chain is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
wordpress-cors-xmlrpc-rce-chain compared with similar skills
All 4 of these similar skills score higher than wordpress-cors-xmlrpc-rce-chain; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| wordpress-cors-xmlrpc-rce-chain (this skill)by uphiago | 84 | 1.3k | 29d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
Frequently asked questions
- How do I install wordpress-cors-xmlrpc-rce-chain?
- Run
npx skills add uphiago/recon-skills --skill wordpress-cors-xmlrpc-rce-chain. The install tabs above show the steps for each supported agent. - Which AI agents does wordpress-cors-xmlrpc-rce-chain work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is wordpress-cors-xmlrpc-rce-chain safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is wordpress-cors-xmlrpc-rce-chain still maintained?
- The repository was last updated 29 days ago, so wordpress-cors-xmlrpc-rce-chain is actively maintained.
Skill content
View source on GitHubname: wordpress-cors-xmlrpc-rce-chain description: Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path. version: 2.0.0 license: MIT platforms: [linux, macos] compatibility: Requires curl, a browser, and approved WordPress test identities tags: [wordpress, cors, xmlrpc, chain, validation] category: redteam related_skills:
- cross-attack-chains
- hunt-cors
- hunt-wordpress
- triage-validation
- xmlrpc-exploitation
WordPress CORS, XML-RPC, and Upload Chain
This skill evaluates whether independently verified WordPress behaviors can form a path to unauthorized file execution. It does not assume that CORS, XML-RPC, registration, or an upload method is exploitable merely because it is present.
When to Use
- Credentialed CORS exposes non-public WordPress data.
- XML-RPC returns a protocol-valid method list.
- An approved test identity has an upload-capable role.
- A plugin or core upload operation may accept an executable file.
- The assessment explicitly permits state-changing upload and execution tests.
Prerequisites
- Explicit authorization for each state-changing step.
- An approved synthetic account and test site or disposable content.
- Browser evidence for the CORS primitive.
- Protocol-valid XML-RPC evidence.
- Confirmed role capabilities and upload path.
- A benign test artifact and cleanup procedure.
How to Run
Create an evidence matrix before sending a state-changing request:
Primitive State Evidence
Credentialed CORS observed browser reads approved non-public data
XML-RPC method observed protocol-valid methodResponse
Upload-capable identity unverified role and capability still required
Executable storage path unverified handler and server behavior required
Cleanup planned test artifact and account removal
Stop when any prerequisite remains inferred.
Procedure
1. Validate Credentialed CORS
Use hunt-cors to prove that an untrusted origin can read non-public data with
an approved browser session. Header reflection or public REST content is not
enough.
Record which information the primitive supplies to the next step. Usernames, nonces, or plugin metadata have different security value and may not enable authentication or upload.
2. Classify XML-RPC
TARGET="https://www.example.test"
OUTPUT_DIR="${OUTPUT_DIR:-./output/wordpress-chain}"
mkdir -p "$OUTPUT_DIR"
curl -sS --max-time 15 \
-X POST "$TARGET/xmlrpc.php" \
-H 'Content-Type: text/xml' \
--data-binary \
'<methodCall><methodName>system.listMethods</methodName></methodCall>' \
-o "$OUTPUT_DIR/xmlrpc-methods.xml"
Require a valid methodResponse. Method presence does not establish that the
current identity may call it.
3. Verify the Approved Identity and Role
Use only the approved test identity. Confirm its current WordPress role and the
specific upload_files or plugin capability needed by the candidate operation.
Default subscriber registration usually does not provide upload capability.
Do not use password spraying or credentials obtained outside the assessment to bridge a missing prerequisite.
4. Validate Upload Without Executing Code
When upload testing is explicitly authorized:
- upload a uniquely named inert text or image file;
- record the method, identity, response, media ID, and final URL;
- verify the stored content and content type;
- delete the artifact and record cleanup.
This demonstrates the upload boundary without introducing executable code.
5. Evaluate Execution Separately
File execution is a distinct prerequisite. Establish whether the upload directory executes the relevant file type, whether extension or MIME validation can be bypassed, and whether a plugin-specific handler moves the artifact.
Use a benign marker approved for the test environment. Do not deploy a command shell. If execution cannot be demonstrated safely, report upload capability and execution as separate observed and inferred states.
6. Assemble the Chain
CORS read
-> information required by approved test identity
-> authorized XML-RPC or plugin operation
-> inert upload accepted
-> executable handling independently confirmed
-> benign marker observed
-> artifact removed
For every arrow, record why the previous step enables the next. Use
cross-attack-chains and triage-validation before assigning compound impact.
Pitfalls
- Public REST user data may not supply credentials or a privileged identity.
- XML-RPC is a feature; method presence is not an authorization bypass.
- Subscriber and customer roles normally cannot upload arbitrary files.
- Upload acceptance does not prove executable storage.
- A plugin version match does not prove the vulnerable route and prerequisite.
- Combining several medium-confidence signals does not create a high-confidence chain.
Verification
- CORS impact is reproduced in a browser with approved non-public data.
- XML-RPC evidence contains a protocol-valid response.
- The exact test identity and required capability are recorded.
- Upload validation uses an inert synthetic artifact and includes cleanup.
- Execution, when authorized, uses a benign marker in a disposable environment.
- Every chain step is confirmed independently; missing steps remain labeled inferred or not tested.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
