
Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and REST API security checks. Developed by Ebrahim Shafiei (EbraSha) for cybersecurity research, penetration testing, and WordPress security assessment.
Abdal CVE-2026-63030 is a defensive WordPress exposure verifier for the REST API batch route confusion tracked as CVE-2026-63030. The issue can be chained with CVE-2026-60137 on affected WordPress releases and may lead to remote code execution.
The tool helps administrators, incident responders, and authorized security teams quickly triage one website or a list of websites without reproducing the weaponized vulnerability chain.
Checking many WordPress installations manually is slow and inconsistent. This verifier automates safe HTTP-based inspection, WordPress version discovery, REST batch endpoint checks, and verdict classification so exposed systems can be prioritized for remediation.
| WordPress branch | Affected versions | Fixed version |
|---|---|---|
| 6.9.x | 6.9.0 through 6.9.4 | 6.9.5 or later |
| 7.0.x | 7.0.0 through 7.0.1 | 7.0.2 or later |
Sites on older or unsupported branches should be moved to a currently maintained WordPress release even when they are not included in the affected range above.
/wp-json/batch/v1 and /?rest_route=/batch/v1.VULNERABLE, AFFECTED, AFFECTED-WAF, PATCHED, NOT-AFFECTED, UNKNOWN, NOT-WORDPRESS, INVALID, or ERROR when applicable.Run the Windows executable:
Abdal-CVE-2026-63030.exe
Then follow the interactive prompts:
Example target file:
https://wordpress.example
https://blog.example
Only scan systems you own or are explicitly authorized to assess.
| Verdict | Meaning |
|---|---|
VULNERABLE | The observed version and endpoint behavior strongly match the affected profile. |
AFFECTED | The detected version is within the affected range, but endpoint evidence is incomplete. |
AFFECTED-WAF | The version appears affected while a WAF or access control may be interfering with verification. |
PATCHED | The detected WordPress version includes the vendor fix. |
NOT-AFFECTED | The detected version is outside the published affected range. |
UNKNOWN | Available evidence is insufficient for a reliable classification. |
NOT-WORDPRESS | WordPress could not be identified on the target. |
INVALID | The supplied target is not a valid URL or input. |
ERROR | A network, TLS, timeout, or HTTP-processing error prevented verification. |
This software is provided solely for lawful defensive security testing, asset-owner verification, education, and authorized research. You are responsible for obtaining permission before scanning any system and for complying with all applicable laws, contracts, and policies.
The software and its results are provided as is, without warranties or guarantees of accuracy, availability, fitness for a particular purpose, or absence of false positives and false negatives. The programmer and contributors are not responsible for misuse, service disruption, data loss, security incidents, or any direct or indirect damages arising from use of this project.
If you encounter any issues or have configuration problems, please reach out via email at [email protected]. You can also report issues on GitLab or GitHub.
If you find this project helpful and would like to support further development, please consider making a donation:
Handcrafted with Passion by Ebrahim Shafiei (EbraSha)
This project is licensed under the AGPLv3 License.