Jason Taylor Avatar

Jason Taylor

Jason has a passion for asking “what-if” questions and for trying to “break” software and test how it responds to unintended uses. Jason has a background in System Administration and Security Engineering in the financial sector. He holds both defensive and offensive certifications including OSCP, PNPT, GCIH, CASP+, and is Splunk Certified. When he’s not spending his time taking new training courses, he loves spending time with his wife and kids and occasionally working on an IoT project to automate some aspect of their greenhouse or chicken coop.

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines

The Exploit articles written by Jason Taylor

  • wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability

    wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability

    It’s rare for WordPress itself to have CVEs. CVE-2026-63030 and CVE-2026-60137 combine to create the critical unauthenticated to RCE vulnerability wp2shell.
    Jason Taylor July 30, 2026
  • Rapid Web Host Recon with GoWitness

    Rapid Web Host Recon with GoWitness

    Enumerating webpages during an internal network pentest can be a large task, but GoWitness makes it easy to focus on high value webpages. Learn how it works.
    Jason Taylor July 28, 2026
  • usbliter8 - Apple A12 and A13 SecureROM Exploit

    usbliter8 – Apple A12 and A13 SecureROM Exploit

    The usbliter8 SecureROM exploit is big news for jailbreaking iPhones. This hardware vulnerability cannot be fixed with a software update.
    Jason Taylor July 3, 2026
  • Building Security Tools from Source to Bypass Endpoint Security

    Building Security Tools from Source to Bypass Endpoint Security

    Endpoint security detects many malicious files created with pentest tools, but pentesters can sometimes bypass this by rebuilding source code. Learn how here.
    Jason Taylor June 16, 2026
  • CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation

    CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation

    Raxis Lead Pentester Jason Taylor recently discovered CVE-2026-36748, a high-risk XSS vulnerability in Rock RMS that allows privilege escalation to admin.
    Jason Taylor June 1, 2026
  • Copy Fail - Local Linux Privilege Escalation in 4 lines

    Copy Fail – Local Linux Privilege Escalation in 4 lines

    CVE-2026-31431, dubbed Copy Fail, allows privilege escalation to root on Linux distros missing the latest kernel patches. Learn what to do in this blog.
    Jason Taylor May 8, 2026