wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
-
Updated
Aug 11, 2026 - Python
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1
WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, allowing unauthenticated attackers to execute arbitrary SQL queries and achieve Remote Code Execution (RCE) on vulnerable WordPress installations.
Pre-auth RCE PoC for CVE-2026-63030 / CVE-2026-60137 (WordPress core)
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and REST API security checks. Developed by Ebrahim Shafiei (EbraSha) for cybersecurity research, penetration testing, and WordPress security assessment.
PoC for the WordPress 6.9/7.0 REST batch-route confusion and author__not_in SQL injection chain.
WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)
Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
Critical Wordpress to Shell (unauthenticated)
WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)
WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.
Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk site lists. For authorized security testing only.
WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
To associate your repository with the cve-2026-63030 topic, visit your repo's landing page and select "manage topics."