
wp2shell-poc
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
authenticationcommand-and-controlexploitation+5
749

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.