
Proof-of-concept exploit for CVE-2019-9787, demonstrating CSRF-to-RCE in WordPress 5.0 via comment injection. Includes Docker setup for isolated testing.
PoC of CVE-2019-9787 CSRF
WordPress Version 5.0
refference
Do not use this except for test purpose.
$ docker-compose up -d

click the link posted at 2.

you'll see the comment "csrf success" is posted by user you currently logged in.