wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
-
Updated
Jul 20, 2026 - Python
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk site lists. For authorized security testing only.
Add a description, image, and links to the wp2shell-poc topic page so that developers can more easily learn about it.
To associate your repository with the wp2shell-poc topic, visit your repo's landing page and select "manage topics."