
Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)
A standalone, read-only WordPress plugin that scans your database and plugin directory for signs that the wp2shell core chain (CVE-2026-63030 + CVE-2026-60137) was exploited — even if it happened weeks ago or the attacker cleaned up. It changes nothing on your site. It is safe to run on any install, patched or not.
This plugin does NOT mitigate the vulnerability. To temporarily protect an unpatched site, use the separate wp2shell Temporary Hotpatch (or just update core). Update to 6.9.5 / 7.0.2 / 6.8.6 as the real fix.

Download the zip above, then Plugins → Add New → Upload Plugin → select the zip → Install →
Activate. Open wp2shell Scanner in the admin menu, then click Run scan to see the scored
verdict and the severity-graded findings. Use Export report (.zip) to download the result plus the raw
database rows an investigator needs — the exploit hides its SQL injection and admin creation in a
request body that web servers don't log, so those DB artifacts are the primary evidence. The archive
holds the report (JSON + text), the relevant oembed_cache / customize_changeset / suspect-post /
suspect-user / orphaned-usermeta rows and changed plugin files (never password hashes), and a
LOG-COLLECTION-GUIDE.txt for the server-side logs to gather by hand. Remove the plugin any time with
the Remove this plugin button on the scan screen (or deactivate/delete normally).
Weighted, read-only indicators map to a score: 50+ Multiple indicators, 25–49 Some indicators,
under 25 No indicators. The strongest signal is the oembed_cache group (loopback reference /
count-of-three / date window), plus high-parent-ID and PoC-titled posts, customize_changeset
entries, wp2_ logins and @wp2shell.invalid emails, new non-founder admins, orphaned usermeta,
wp_users id gaps, and leftover wp2shell_* webshell files or directories. It does not rely on any
single naming convention.
This scanner is best-effort, not proof. It looks for known leftover traces of one specific exploit chain, so its output can be wrong in both directions:
It is not a substitute for updating WordPress core or for a proper incident investigation by a qualified professional. Do not make remediation, disclosure, or "all clear" decisions on this tool's output alone.
This software is provided "as is", without warranty of any kind, express or implied, including
merchantability, fitness for a particular purpose, and non-infringement. To the maximum extent
permitted by law, the authors, contributors, and distributors accept no liability for any damage,
data loss, downtime, false positives, false negatives, missed detections, or for any action taken or
not taken based on its output — direct, indirect, incidental, or consequential. You are solely
responsible for ensuring you are authorized to run it on a given site and for independently
verifying its results. Use entirely at your own risk. Licensed under the GNU GPL v3 (see LICENSE).