Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wp2shell-compromise-scanner-plugin — Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137) | Kitploit
Tools/GitHubGitHub/eyesecurity/wp2shell-compromise-scanner-plugin
Indicator of Compromise (IOC) ManagementVulnerability ScannersForensicsWeb SecurityDigital ForensicsIntrusion DetectionIncident ResponseDatabase Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
eyesecurity/wp2shell-compromise-scanner-plugin

wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

View Repository
1312 months agoNot yet reviewed

Compromise Scanner for wp2shell (read-only)

A standalone, read-only WordPress plugin that scans your database and plugin directory for signs that the wp2shell core chain (CVE-2026-63030 + CVE-2026-60137) was exploited — even if it happened weeks ago or the attacker cleaned up. It changes nothing on your site. It is safe to run on any install, patched or not.

This plugin does NOT mitigate the vulnerability. To temporarily protect an unpatched site, use the separate wp2shell Temporary Hotpatch (or just update core). Update to 6.9.5 / 7.0.2 / 6.8.6 as the real fix.

The scan screen: version status, forensic verdict and score, and severity-graded findings

Get it

  • Download: latest release as .zip
  • WordPress plugin directory: (link goes live once the plugin is approved on WordPress.org)

Install

Download the zip above, then Plugins → Add New → Upload Plugin → select the zip → Install → Activate. Open wp2shell Scanner in the admin menu, then click Run scan to see the scored verdict and the severity-graded findings. Use Export report (.zip) to download the result plus the raw database rows an investigator needs — the exploit hides its SQL injection and admin creation in a request body that web servers don't log, so those DB artifacts are the primary evidence. The archive holds the report (JSON + text), the relevant oembed_cache / customize_changeset / suspect-post / suspect-user / orphaned-usermeta rows and changed plugin files (never password hashes), and a LOG-COLLECTION-GUIDE.txt for the server-side logs to gather by hand. Remove the plugin any time with the Remove this plugin button on the scan screen (or deactivate/delete normally).

Verdict

Weighted, read-only indicators map to a score: 50+ Multiple indicators, 25–49 Some indicators, under 25 No indicators. The strongest signal is the oembed_cache group (loopback reference / count-of-three / date window), plus high-parent-ID and PoC-titled posts, customize_changeset entries, wp2_ logins and @wp2shell.invalid emails, new non-founder admins, orphaned usermeta, wp_users id gaps, and leftover wp2shell_* webshell files or directories. It does not rely on any single naming convention.

Important — please read

This scanner is best-effort, not proof. It looks for known leftover traces of one specific exploit chain, so its output can be wrong in both directions:

  • A Some indicators or Multiple indicators verdict is not confirmation of a breach — indicators can have innocent causes (false positives), and every flagged item must be verified by a human.
  • A No indicators verdict is not a guarantee — a careful attacker can remove their own traces and a different or future attack may leave none (false negatives).

It is not a substitute for updating WordPress core or for a proper incident investigation by a qualified professional. Do not make remediation, disclosure, or "all clear" decisions on this tool's output alone.

Legal

This software is provided "as is", without warranty of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. To the maximum extent permitted by law, the authors, contributors, and distributors accept no liability for any damage, data loss, downtime, false positives, false negatives, missed detections, or for any action taken or not taken based on its output — direct, indirect, incidental, or consequential. You are solely responsible for ensuring you are authorized to run it on a given site and for independently verifying its results. Use entirely at your own risk. Licensed under the GNU GPL v3 (see LICENSE).

Download Tool