Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-63030 — Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE, database read, and webshell deployment. | Kitploit
Tools/GitHubGitHub/langz337/cve-2026-63030
Privilege EscalationVulnerability ScannersExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingCommand and ControlRed TeamingPayload DevelopmentRemote Access Trojan
11 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHublangz337/cve-2026-63030

CVE-2026-63030

Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE, database read, and webshell deployment.

View Repository

LANGZ — wp2shell Exploit Tool

Author: LANGZ
CVE: CVE-2026-63030 (Chained with CVE-2026-60137)
Severity: Critical (CVSS 9.8)
Type: Pre-Authentication Remote Code Execution (RCE)


⚠️ Disclaimer

This tool is provided strictly for educational purposes and authorized security testing only.

By using this tool, you agree that:

  • You will only use it against systems you own or have explicit written permission to test.
  • You will not use it for any illegal, unauthorized, or malicious activity.
  • The author (LANGZ) is not responsible for any damage, data loss, legal consequences, or misuse caused by this tool.
  • Any misuse of this tool is entirely the responsibility of the user.

If you use this tool against a system without authorization, you are committing a crime.
The author does not condone, support, or take any responsibility for such actions.


📌 Impact

CVE-2026-63030 is a REST API batch-route confusion flaw (CWE-436) in WordPress core, introduced in version 6.9. When chained with CVE-2026-60137 (a blind SQL injection in WP_Query's author__not_in parameter), it allows an unauthenticated attacker to achieve full remote code execution on a default WordPress installation.

What an attacker can do:

  • Read the entire WordPress database (including password hashes)
  • Create new administrator accounts
  • Upload and execute arbitrary PHP files (webshells)
  • Execute OS-level commands on the server
  • Fully take over the website and server

Why it's dangerous:

  • Zero plugins required — affects stock WordPress installations
  • Zero configuration changes needed
  • Single HTTP request can trigger the full chain
  • Public PoC exploits and Nuclei templates are circulating
  • CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026, with a remediation deadline of July 24, 2026

🛡️ Mitigation

1. Immediate Patch (Recommended)

Update WordPress to a patched version:

Current VersionUpdate To
6.9.0 – 6.9.46.9.5
7.0.0 – 7.0.17.0.2
6.8.0 – 6.8.56.8.6 (SQLi fix only)

Note: WordPress enabled forced auto-updates, but sites with auto-updates disabled or managed hosting that delays updates remain exposed. Verify the update was successfully applied.

2. Temporary Workarounds (If Patching Is Delayed)

  • Block the batch endpoint at the WAF or reverse proxy:
    • Block POST requests to /wp-json/batch/v1
    • Block POST requests to ?rest_route=/batch/v1
  • Restrict anonymous REST API access using a security plugin (e.g., "Disable WP REST API")
  • Deploy a WAF with WordPress-specific rule sets to detect and block SQL injection attempts
  • Limit database user privileges — prevent the WordPress DB account from performing file writes or high-impact SQL operations

3. Detection & Post-Exploitation Checks

Look for:

  • Unusual POST requests to /wp-json/batch/v1 or ?rest_route=/batch/v1 in access logs
  • Unknown administrator accounts
  • Suspicious PHP files in /wp-content/cache/ or other web-accessible directories
  • Unexpected plugins or modified core files

If you find indicators of compromise, simply removing the files and admin account is not enough. Perform a full incident response and consider a complete system rebuild.


⚙️ How the Exploit Works

The exploit chain combines two vulnerabilities:

Step 1: Route Confusion (CVE-2026-63030)

WordPress's REST API batch processor (serve_batch_request_v1) has an off-by-one indexing bug. When wp_parse_url() fails on a sub-request path (e.g., "///"), the resulting WP_Error is pushed to $validation[] but not to $matches[]. This desynchronizes the two arrays, causing every subsequent request to be dispatched under the wrong handler.

By nesting a carefully structured batch inside another batch, an attacker can route a request validated by one endpoint's schema through a completely different endpoint's callback — bypassing permission checks entirely.

Step 2: SQL Injection (CVE-2026-60137)

The confused request lands in WP_Query's author__not_in parameter. WordPress casts the string to an array but skips absint() sanitization, allowing raw SQL injection. The tool uses this to:

  • Read the database (UNION SELECT)
  • Poison WordPress's object cache with fake WP_Post objects
  • Trigger a changeset auto-publish that elevates privileges
  • Re-enter the REST API with admin context

Step 3: Full Chain Execution

Once the setup is complete (discovering table prefix and admin ID), the escalation payload fires in a single HTTP request:

  1. Cache poisoning (fake posts via UNION)
  2. Privilege escalation (changeset auto-publish)
  3. User creation (admin account)

The tool then uses the generated admin credentials to deploy a plugin-based webshell for OS command execution.


🚀 How to Run

Requirements

  • Python 3.8+
  • No external dependencies (uses only standard library)

Basic Usage

root@kitploit:~
# Single target check
python3 wp2shell.py http://target.com

# Check with active SQLi confirmation
python3 wp2shell.py http://target.com --confirm-sqli

# Read database (fingerprint)
python3 wp2shell.py http://target.com --read --preset fingerprint

# Read user logins and password hashes
python3 wp2shell.py http://target.com --read --preset users

# Deploy webshell and run a command
python3 wp2shell.py http://target.com --shell --cmd id

# Interactive shell
python3 wp2shell.py http://target.com --shell -i

# Mass scan from file
python3 wp2shell.py targets.txt

Interactive Menu

Run without arguments to open the interactive menu:

root@kitploit:~
python3 langz.py
root@kitploit:~
══════════════════════════════════════════════════════════════
   ██╗      █████╗ ███╗   ██╗ ██████╗ ███████╗
   ██║     ██╔══██╗████╗  ██║██╔════╝ ╚══███╔╝
   ██║     ███████║██╔██╗ ██║██║  ███╗  ███╔╝
   ██║     ██╔══██║██║╚██╗██║██║   ██║ ███╔╝
   ███████╗██║  ██║██║ ╚████║╚██████╔╝███████╗
   ╚══════╝╚═╝  ╚═╝╚═╝  ╚═══╝ ╚═════╝ ╚══════╝

        ▓▒░  L A N G Z   T O O L S  ░▒▓
             Author : LANGZ
             CVE    : (CVE-2026-63030)
──────────────────────────────────────────────────────────────
  [1] Single Target  - Check
  [2] Mass Target    - Check
  [3] Single Target  - Auto Admin
  [4] Mass Target    - Auto Admin
  [5] Exit
──────────────────────────────────────────────────────────────
  Results -> Results/results.txt
══════════════════════════════════════════════════════════════

Options


🔗 CVE Reference

  • CVE-2026-63030 — https://nvd.nist.gov/vuln/detail/CVE-2026-63030
  • CVE-2026-60137 — https://nvd.nist.gov/vuln/detail/CVE-2026-60137
  • WordPress Security Release — https://wordpress.org/news/2026/07/wordpress-7-0-2/
  • CISA KEV Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • Nuclei Template — https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-63030.yaml

📜 License

This project is provided for educational and authorized security testing purposes only.
The author LANGZ assumes no liability for any misuse or damage caused by this tool.


Author: LANGZ
CVE: CVE-2026-63030

Download Tool
AspectDetail
Affected VersionsWordPress 6.9.0 – 6.9.4, WordPress 7.0.0 – 7.0.1
SQLi-Only AffectedWordPress 6.8.0 – 6.8.5 (CVE-2026-60137 only)
Authentication RequiredNone
User InteractionNone
ImpactComplete site compromise — database read/write, arbitrary PHP file upload, OS command execution
Exploitation StatusActively exploited in the wild; 62,802+ unique attacking IPs observed
FlagDescription
--timeoutRequest timeout in seconds (default: 15)
--proxyHTTP proxy (e.g., http://127.0.0.1:8080)
--threadsParallel threads for mass scan (default: 50)
--sleepSQL timing delay for blind confirmation (default: 3)
--samplesTiming pairs for confirmation (default: 3)
--confirm-sqliSend active SQLi confirmation payload
--presetfingerprint or users
--queryCustom SQL expression to read
--prefixDatabase table prefix (default: wp_)
--max-lengthMax characters per value (default: 128)
--techniqueauto, union, blind, or error
--userAdmin username (for --shell)
--passwordAdmin password (for --shell)
--cmdCommand to run on target
-i, --interactiveOpen interactive shell