Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-60137 — wpsqli full SQLi extractor + dumper for CVE-2026-60137 | Kitploit
Tools/GitHubGitHub/adarshthakur14777-cyber/cve-2026-60137
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingDatabase Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
adarshthakur14777-cyber/cve-2026-60137

CVE-2026-60137

wpsqli full SQLi extractor + dumper for CVE-2026-60137

View Repository
201 month agoNot yet reviewed

wpsqli - WordPress SQLi Extractor (CVE-2026-60137)

A fast, menu-driven database extraction tool exploiting the author__not_in SQL injection vulnerability in WordPress core. This tool focuses purely on database enumeration and dumping, utilizing the REST batch route confusion (CVE-2026-63030) to reach the SQLi sink unauthenticated.


Table of Contents

  • Overview
  • Vulnerability Chain
  • Affected Versions
  • Features
  • Installation
  • Usage
  • Menu Options
  • Extraction Modes
  • Performance
  • Legal Disclaimer

Overview

wpsqli is a pure Python tool designed to exploit a chained vulnerability in WordPress core that allows unauthenticated SQL injection into the database. It bypasses WordPress REST API validation via a batch route confusion bug, delivering a raw string payload directly to the WP_Query SQL sink.

This tool is built for speed and flexibility: it automatically attempts UNION-based in-band extraction (instant), falls back to 8-thread parallel boolean-blind extraction, and finally to sequential time-based extraction if needed.


Vulnerability Chain

This tool chains two independent vulnerabilities to achieve unauthenticated database extraction:

Bug A — author__not_in SQL Injection (CVE-2026-60137)

Location: wp-includes/class-wp-query.php, WP_Query::get_posts()

The author__not_in parameter only applies absint() sanitization if the input is an array. If a string is passed, the is_array() guard is skipped, the string passes through implode() unchanged, and is concatenated raw into the SQL $where clause.

// Line 2404: guard only fires for ARRAYS
if ( is_array( $query_vars['author__not_in'] ) ) {
    $query_vars['author__not_in'] = array_unique( array_map( 'absint', $query_vars['author__not_in'] ) );
    sort( $query_vars['author__not_in'] );
}
// Line 2408: string passes straight through
$author__not_in = implode( ',', (array) $query_vars['author__not_in'] );
// Line 2409: raw interpolation
$where .= " AND {$wpdb->posts}.post_author NOT IN ($author__not_in) ";

Bug B — REST Batch Route Confusion (CVE-2026-63030)

The REST API posts endpoint maps author_exclude to author__not_in but declares it as type => 'array' of integers, so core coerces/rejects a string. Bug B smuggles the string past validation by abusing a desynchronization bug in the REST batch endpoint (/wp-json/batch/v1). By injecting a malformed path primer that wp_parse_url() rejects, a WP_Error is seeded into the batch request list, desyncing $matches from $validation. This allows a following sub-request to be dispatched under the wrong handler without parameter validation.


Affected Versions

Version RangeStatus
6.8.0 – 6.8.5SQLi bug present, but chain NOT reachable (batch confusion introduced in 6.9.0)
6.9.0 – 6.9.4VULNERABLE — full unauth chain
7.0.0 – 7.0.1VULNERABLE — full unauth chain
6.8.6Patched (SQLi)
6.9.5Patched
7.0.2Patched
7.1-beta2+Patched

Caveat: The SQLi sink is only reached when a persistent object cache (Redis/Memcached) is NOT in use.


Features

  • No Dependencies: Pure Python standard library. No pip install required.
  • Three-Tier Extraction:
    • UNION-based: Forges a fake wp_posts row to extract entire strings in a single HTTP request (instant).
    • Boolean-blind (Parallel): If UNION is blocked by object caching, uses 8 parallel threads with binary search to extract ~7 requests per character.
    • Time-based (Sequential): Fallback if boolean oracle returns no rows.
  • Full Enumeration: List databases, tables, and columns.
  • Table Dumping: Dump individual tables, all tables in a DB, or a full nuclear dump to a timestamped text file.
  • Graceful Interruption: Ctrl+C during extraction stops the current query and returns partial results without crashing the session.
  • Session Persistence: Connect once and run multiple queries via the interactive menu.
  • URL Sanitization: Automatically strips paths/queries from host input to prevent endpoint doubling.
  • Crack-Ready Output: User dumps include ID|user_login|user_pass format with bcrypt hashes ready for hashcat -m 35500.

Installation

No installation required. Just download and run:

# Clone the repository
git clone https://github.com/AdarshThakur14777-cyber/CVE-2026-60137.git
# Navigate to directory
cd CVE-2026-60137

# Run
python main.py

Requirements:

  • Python 3.8+
  • No external packages needed (stdlib only)

Usage

Launch the interactive menu:

python main.py

Example Session

============================================================
  WP SQLi Extractor v3 (CVE-2026-60137)
============================================================
------------------------------------------------------------
  CONNECTION
   0. Connect / Change target
   1. Check target (version + vuln confirm)
------------------------------------------------------------
  FINGERPRINTING
   2. MySQL version (@@version)
   3. Current database name
   4. Current DB user
   5. WordPress table prefix
   6. Dump wp_users (ID, login, pass hash)
   7. Custom SQL query
   8. Extract all fingerprints (2+3+4+5)
------------------------------------------------------------
  ENUMERATION
   9. List all databases
  10. List all tables (current DB)
  11. List columns of a table
------------------------------------------------------------
  DUMPING
  12. Dump a specific table
  13. Dump all tables (current DB)
  14. Full dump to file (all tables + all rows)
------------------------------------------------------------
  15. Exit
============================================================

Choice: 0
Target (https://example.com): https://target.com
Skip TLS verify? (y/N):
Sleep delay for time-based (default 3):

[*] Connecting to https://target.com ...
[+] Batch endpoint: https://target.com/wp-json/batch/v1
[*] WordPress version: 6.9.4 VULNERABLE
[*] Testing UNION-based extraction ...
[!] UNION not available — trying boolean blind (8 parallel threads) ...
[+] Boolean-blind mode active (8 threads, ~7 reqs/char)
[+] Time-based also works (0.69s vs 3.78s)

Menu Options

Connection

OptionDescription
0Connect to a target (sanitizes URLs automatically)
1Verify vulnerability and active extraction mode

Fingerprinting

OptionDescription
2Extract MySQL version (SELECT @@version)
3Extract current database name (SELECT DATABASE())
4Extract current DB user (SELECT CURRENT_USER())
5Extract WordPress table prefix
6Dump wp_users table (ID, login, password hash)
7Run a custom SQL query
8Run all fingerprints (options 2-5) in sequence

Enumeration

OptionDescription
9List all databases on the MySQL server
10List all tables in current or specified database
11List all column names for a specific table

Dumping

OptionDescription
12Dump a single table (with optional row limit and file save)
13Dump all tables in current database
14Full nuclear dump — all tables + all rows to timestamped file

Extraction Modes

The tool automatically attempts three extraction modes in order of speed:

1. UNION-Based (Instant)

Forges a fake wp_posts row with the extracted value hex-encoded in the post_title column (wrapped in ||..|| markers). The REST API reflects it back in the response — entire string in a single HTTP request.

  • 1 request per query
  • Works only when no persistent object cache is active
  • Uses CONCAT(0x7c7c, HEX(CAST((<expr>) AS CHAR)), 0x7c7c) to encode the result
Download Tool