Feed/CVE-2026-63030
CVE-2026-63030CRITICALCVSS 9.8CISA KEV: Actively Exploited

CVE-2026-63030

Published Jul 17, 2026·Updated Jul 22, 2026

NVD Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Public Exploits & PoCs65 found

[POC] CVE-2026-63030 — wp2shell

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

7

PoC: WP2Shell

WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, allowing unauthenticated attackers to execute arbitrary SQL queries and achieve Remote Code Execution (RCE) on vulnerable WordPress installations.

5

[POC] CVE-2026-63030 — wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

4

[POC] CVE-2026-63030 — wp2shell-poc

WordPress REST API SQLi to RCE (CVE-2026-63030)

4

[POC] CVE-2026-63030 — wp2shell-poc

CVE-2026-63030

4

[POC] CVE-2026-63030 — wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.

3

[POC] CVE-2026-63030 — wp2shell-lab

Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1

2

[POC] CVE-2026-63030 — wp2shell-detect

Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

1

[POC] CVE-2026-63030 — wp2shell

wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)

1

[POC] CVE-2026-63030 — sxwp2shell

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

1

[POC] CVE-2026-63030 — CVE-2026-63030

Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).

1

PoC: wp2shell-Exploit-Waf-Bypass

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

1

PoC: CVE-2026-63030

CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept

1

PoC: wp2shell-scan

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

1

PoC: CVE-2026-63030

PoC Exploit of WordPress Core Unauthenticated RCE known as WP2Shell

1

PoC: wp2shell-scanner

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

1

PoC: wp2shell-poc

wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

PoC: cve-2026-63030-lab

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

PoC: WP2Shell

WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials.

PoC: CVE-2026-63030

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

PoC: wp2shell-PoC

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

PoC: wp2exp-2026

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).

PoC: wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

PoC: CVE-2026-63030-WP2Shell

CVE-2026-63030 Exploit | by gr1tx

PoC: wp2shell-Hestia-Scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.

PoC: wp2shell

CVE-2026-63030 + CVE-2026-60137+poc

PoC: WordPress-CVE-2026-63030-Analysis

Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.

PoC: CVE-2026-63030

WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)

PoC: cve-2026-63030_60137-wordpress_rce_reproduction

CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

PoC: CVE-2026-63030-CVE-2026-60137-wp2shell-poc

CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc

PoC: wp2shell-poc-fulljs

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

PoC: wp2shell-vulnerability-scanner

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.

PoC: WP2Shell-CVE-2026-63030-POC

PoC detector & safe validator for the WP2Shell WordPress vulnerability chain: CVE-2026-63030 (REST batch-route confusion) + CVE-2026-60137 (author__not_in SQL injection). For authorized security testing only.

PoC: wp2shell-Wordpress-TOWN

Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.

PoC: wp2shell-cf-WAF-bypass

wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)

PoC: wp2shell

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

PoC: wp2shell-checker

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

PoC: wp2shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

PoC: wordpress-batch-rce-lab

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

PoC: PressVector

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

PoC: wordpress-skelersecurity-core-security-CVE-2026-63030

The wp2shell vulnerability chain represents one of the most significant WordPress Core security issues in recent years. Because exploitation begins with an unauthenticated request and can ultimately result in Remote Code Execution, organizations should treat remediation as an emergency.

PoC: wp-cve-2026-63030-check

Non-intrusive exposure checker for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 / CVE-2026-60137).

PoC: wp2shell-lab

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

PoC: wp2shell-scanner

WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.

PoC: CVE-2026-63030-POC

CVE-2026-63030 / wp2shell

PoC: wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

PoC: wp2shell-scanner

CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner

PoC: wp2shell

wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

PoC: Wp2Shell

Exploit POC for Wp2Shell, CVE-2026-63030 + CVE-2026-63137

PoC: CVE-2026-63030

WordPress 未授权RCE EXP | CVE-2026-63030

PoC: CVE-2026-63030_PoC

CVE-2026-63030 - WordPress Core Pre-Auth RCE Mass Exploit

PoC: wp2shell-scan

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

PoC: WordPresShell

Pre-auth RCE PoC for CVE-2026-63030 / CVE-2026-60137 (WordPress core)

PoC: abdal-cve-2026-63030

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and REST API security checks. Developed by Ebrahim Shafiei (EbraSha) for cybersecurity research, penetration testing, and WordPress security assessment.

PoC: wp2shell_scanner

Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation.

PoC: wp2shell

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk site lists. For authorized security testing only.

PoC: CVE-2026-63030

CVE-2026-63030

PoC: CVE-2026-63030

A critical unauthenticated "remote code execution" vulnerability affecting WordPress Core

PoC: CVE-2026-63030-wp2r00t

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

PoC: CVE-2026-63030

CVE-2026-63030 (wp2shell) POC.

PoC: wp2shell

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

PoC: wp2shell

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

PoC: wp2shell

wp2shell - WordPress CVE-2026-63030 Exploit & Scanner

PoC: wordpress-cve-2026-63030

Pre-auth RCE in WordPress Core via REST API batch route confusion + WP_Query SQLi (CVE-2026-63030 / CVE-2026-60137). Detection PoC.

PoC: wp2shell-poc2

CVE-2026-63030

Community Discussion

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free