A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
[POC] CVE-2026-60137 — Ultimate-wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137
wpsqli full SQLi extractor + dumper for CVE-2026-60137
[POC] GHSA-6vch-q96h-7gc3 — CVE-2026-60137-With-Skip-SSL
Adding --insecure to skip ssl
[POC] CVE-2026-63030 — CVE-2026-63030-CVE-2026-60137-wp2shell-poc
CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc
[POC] CVE-2026-60137 — wp2shell-poc
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
[POC] CVE-2026-60137 — Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
[POC] CVE-2026-60137 — abdal-cve-2026-60137
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.
[POC] CVE-2026-60137 — wp2shell-poc
wp2shell (CVE-2026-60137 / CVE-2026-63030)
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
[POC] CVE-2026-60137 — wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free