Feed/CVE-2026-6013
CVE-2026-6013HIGHCVSS 8.8

CVE-2026-6013

Published Apr 9, 2026·Updated Jun 17, 2026

NVD Description

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Public Exploits & PoCs10 found

[POC] CVE-2026-60137 — Ultimate-wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

4

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137

wpsqli full SQLi extractor + dumper for CVE-2026-60137

[POC] GHSA-6vch-q96h-7gc3 — CVE-2026-60137-With-Skip-SSL

Adding --insecure to skip ssl

[POC] CVE-2026-63030 — CVE-2026-63030-CVE-2026-60137-wp2shell-poc

CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc

[POC] CVE-2026-60137 — wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

[POC] CVE-2026-60137 — Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

[POC] CVE-2026-60137 — abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.

[POC] CVE-2026-60137 — wp2shell-poc

wp2shell (CVE-2026-60137 / CVE-2026-63030)

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-60137-WordPress-Core-SQL-Injection-PoC

Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.

[POC] CVE-2026-60137 — wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free