@thecybersecguru Maybe I wasn't clear, or I'm misreading the situation... The diagram says:1. rest endpoint2. route confusion3. sqli4. rce but the way you get from 3 to 4 is by cracking the admin passwordThe vuln itself isn't an RCE - it's information disclosure⸸... The code execution comes from "logging in as admin and installing an evil plugin", right? __ ⸸. ... of the hashed admin password, but still