The wp2shell-PoC repository describes a PoC for a chain involving CVE-2026-63030 and CVE-2026-60137 in WordPress core, an example that reproduces a vulnerability. The chain combines batch REST API route confusion and SQL injection.
The description says the chain gives an unauthenticated user a path to full WordPress compromise and remote code execution. The default check mode sends a benign batch marker and does not execute SQL injection.
The wp2shell site lists WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 as affected, with 6.9.5 and 7.0.2 fixed. The site’s authors advise updating WordPress immediately.
Claim check:
- The wp2shell-PoC repository describes a PoC for a chain involving CVE-2026-63030 and CVE-2026-60137 in WordPress core. (confirmed by the publication itself: evidence; «Proof-of-concept for the wp2shell vulnerability chain affecting WordPress Core, combining CVE-2026-63030 and CVE-2026-60137.»)
- The chain combines batch REST API route confusion and SQL injection. (confirmed by the publication itself: evidence; «The project demonstrates the interaction between the REST API Batch route confusion vulnerability and a WP_Query SQL injection»)
- The description says the chain gives an unauthenticated user a path to full WordPress compromise and remote code execution. (confirmed by the publication itself: evidence; «resulting in an unauthenticated path to full WordPress compromise and remote code execution (RCE).»)
- The default check mode sends a benign batch marker and does not execute SQL injection. (confirmed by the publication itself: evidence; «Sends a benign batch marker probe that detects the route confusion bug without executing SQLi payloads.»)
- The wp2shell site lists WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 as affected, with 6.9.5 and 7.0.2 fixed. (confirmed by the publication itself: evidence; «6.9.0 - 6.9.4 affected, fixed in 6.9.5 7.0.0 - 7.0.1 affected, fixed in 7.0.2»)
- The site’s authors advise updating WordPress immediately. (confirmed by the publication itself: evidence; «The best way to protect yourself is to update WordPress immediately.»)
Publications:
Primary sources:
score 73.9 out of 100 · kind: incident