Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wp2shell-poc β€” wp2shell β€” WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137 | Kitploit
Tools/GitHubGitHub/deadexpl0it/wp2shell-poc
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityCTFPenetration TestingLearning & EducationRed Teaming
GitHubdeadexpl0it/wp2shell-poc

wp2shell-poc

wp2shell β€” WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

View Repository
3301 month agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

wp2shell

πŸ’™ Support the Project

If you appreciate my work, consider supporting the project via USDT (TRC20): TQBA72kakjCZLnJt8fJYcD7dyQCEpzNtVN

WordPress Core Pre-Authentication RCE Chain

wp2shell is a security research Proof-of-Concept demonstrating a pre-authentication vulnerability chain in WordPress Core combining:

  • CVE-2026-63030 β€” REST API Batch route confusion
  • CVE-2026-60137 β€” WP_Query SQL injection

The chain demonstrates how these vulnerabilities can be combined to move from an unauthenticated REST API request to SQL injection, privilege escalation, administrator account creation, and ultimately authenticated remote code execution.

[!WARNING]

Authorized Security Research Only

This project is intended for:

  • Vulnerability research
  • Defensive validation
  • Authorized penetration testing
  • Security laboratories
  • CTFs and educational environments

Only test systems that you own or have explicit written authorization to assess.

Do not use this project against third-party infrastructure without authorization.


Table of Contents

  • Overview
  • Vulnerability Chain
  • CVE-2026-63030
  • CVE-2026-60137
  • How the Chain Works
  • Affected Versions
  • Preconditions
  • Features
  • Interactive Menu
  • Recommended Mode β€” Mode 3
  • Mode 1 β€” Fingerprint and Confirm
  • Mode 2 β€” Blind SQL Extraction
  • Mode 3 β€” Pre-Auth Admin Creation
  • Mode 4 β€” Full RCE Chain
  • Mode 5 β€” Facilitated Sink SQLi
  • Mode 6 β€” Threaded URL Scan
  • Mode 7 β€” Transport Settings
  • Mode 8 β€” Change Target URL
  • Single Target vs URL List
  • Detection Logic
  • Technical Chain
  • Route Variants
  • SQLite Support
  • Installation
  • Security Impact
  • Defensive Detection
  • Mitigation
  • Credits
  • References
  • Disclaimer

Overview

wp2shell is a unified WordPress Core security research tool for investigating the interaction between two vulnerabilities:

CVE-2026-63030
        |
        v
REST API Batch Route Confusion
        |
        v
Validation / Dispatch Confusion
        |
        v
CVE-2026-60137
        |
        v
WP_Query SQL Injection
        |
        v
Blind SQL Access
        |
        v
Application / Object-State Manipulation
        |
        v
Privilege Escalation
        |
        v
Administrator Account Creation
        |
        v
Authenticated Code Execution

The PoC is implemented as a Python research tool and uses the Python standard library without requiring third-party Python packages.


Vulnerability Chain

The project combines two WordPress Core vulnerabilities.

                    Unauthenticated Request
                              |
                              v
                   +----------------------+
                   |   CVE-2026-63030     |
                   | REST Batch Route     |
                   |      Confusion       |
                   +----------+-----------+
                              |
                              v
                    Validation Confusion
                              |
                              v
                   +----------------------+
                   |   CVE-2026-60137     |
                   |   WP_Query SQLi      |
                   +----------+-----------+
                              |
                              v
                       Blind SQLi
                              |
                              v
                 Application-State Abuse
                              |
                              v
                    Privilege Escalation
                              |
                              v
                   Administrator Access
                              |
                              v
                    Authenticated RCE

The important security property is the interaction between the two vulnerabilities rather than either vulnerability in isolation.


CVE-2026-63030

REST API Batch Route Confusion

The first vulnerability affects processing of requests through the WordPress REST API Batch endpoint.

The batch implementation maintains request matching and validation information in parallel structures indexed by request position.

A malformed sub-request can cause those structures to become desynchronized.

This creates an off-by-one dispatch condition where a later request can be processed using a handler or validation context associated with another request.

Conceptually:

Request A
   |
   +-- validation entry
   +-- matching entry
   |
   v
Malformed request
   |
   +-- internal state becomes desynchronized
   |
   v
Request B
   |
   +-- unexpected handler / validation context

The PoC performs behavioral checks to determine whether the route confusion is actually reachable.


CVE-2026-60137

WP_Query SQL Injection

The second vulnerability affects a WP_Query SQL processing path.

Once the route-confusion primitive is established, attacker-controlled input can reach the vulnerable query path.

The PoC demonstrates the resulting SQL injection through blind differential testing.

The research functionality includes:

  • Boolean-blind confirmation
  • Optional time-based corroboration
  • Database fingerprinting
  • Supported scalar extraction
  • WordPress user-data research

How the Chain Works

1. REST Batch Route Confusion

An unauthenticated request reaches the WordPress REST Batch endpoint.

A malformed batch sub-request causes the internal request matching and validation state to become desynchronized.

A later request can consequently be processed using an unintended context.


2. SQL Injection

The route-confusion primitive provides the path needed for the second vulnerability.

An attacker-controlled value can reach the vulnerable WP_Query processing path.

This creates a blind SQL injection primitive.


3. Blind SQL Extraction

The SQL injection can be used as a boolean-blind extraction channel.

The PoC contains functionality for researching database information and supported WordPress user information.


4. Application-State Manipulation

The chain uses database-controlled results to influence WordPress application objects and subsequent processing.

This provides the primitives needed by the privilege-escalation stage.


5. Changeset Escalation

The chain uses WordPress changeset processing to establish an administrator execution context.

A fabricated customize_changeset object can participate in the privilege-escalation sequence.


6. Hook Re-entry

The chain re-enters WordPress request processing through the application request lifecycle.

This allows subsequent API processing to occur under the elevated context.


7. Administrator Account Creation

The research PoC implements a pre-authentication administrator creation stage.

This is the key reason Mode 3 is useful for security validation: it demonstrates the privilege-escalation impact without continuing into the webshell/RCE stage.


8. Authenticated Code Execution

Mode 4 extends the research chain beyond administrator creation into the authenticated code-execution stage.

This stage should only be used in an isolated laboratory or an explicitly authorized assessment.


Affected Versions

Complete Pre-Authentication Chain

Download Tool