Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

WP2Shell — CVE-2026-63030 + CVE-2026-60137

WordPress Core Pre-Authentication RCE (mass exploit / detector)

CVE-2026-63030 CVE-2026-60137 CVSS WordPress Auth

Author Python Telegram


📋 Vulnerability Overview

Attribute Details
CVE ID CVE-2026-63030 (+ CVE-2026-60137)
Chain wp2shell — pre-auth RCE
Severity 🔴 CRITICAL (CVSS 9.8)
Target WordPress Core (sem plugins)
Affected (RCE) 6.9.0 – 6.9.4 e 7.0.0 – 7.0.1
Affected (SQLi only) 6.8.0 – 6.8.5
Fixed 6.8.6 / 6.9.5 / 7.0.2 (18/07/2026)
Authentication Required None

🔍 Technical Description

Duas falhas encadeadas no núcleo do WordPress:

  1. CVE-2026-60137 — SQL Injection: injeção SQL no parâmetro author__not_in da classe interna WP_Query.
  2. CVE-2026-63030 — REST API batch route confusion: o endpoint /wp-json/batch/v1 dessincroniza as entradas do batch, fazendo uma requisição "cair" na rota seguinte.

A cadeia converte a SQLi em RCE pré-autenticação:

route confusion /wp-json/batch/v1 ─► SQLi no author__not_in
        │                                    │
        └──────────────┬─────────────────────┘
                       ▼
        UNION fake-post + oEmbed + changeset poisoning
                       ▼
        POST /wp/v2/users  (roles: administrator)  ← admin criado sem auth
                       ▼
        login → upload plugin backdoor → RCE

Fallbacks: INTO OUTFILE direto (FILE privilege) e extração cega de hash + crack.


🚀 Usage

python wp2shell.py exploit -l targets.txt --cmd whoami --authorized -k -c 10 --delay 2
python wp2shell.py remote  -l targets.txt --authorized --active-probe -c 20 -f csv -o scan.csv
Option Description
-l, --targets-file Um alvo por linha (repetível, sem limite)
-u, --target Alvo único
--cmd Comando a executar no alvo
--authorized Obrigatório (ou WP2SHELL_AUTHORIZED=1)
-c, --concurrency Alvos em paralelo (1–32)
--delay SLEEP do timing/extração (2 = robusto)
--rate Requisições/s por alvo
-k, --insecure Ignora TLS
--proxy Proxy HTTP
--wordlist / --password / --username Fallback de credenciais
--log / --owned / --results-csv Ficheiros de saída

📊 Output

[+] [14:22:31] https://target.com  OWNED  ✓1 ~0 ✗10
[~] [14:22:32] https://other.com   ADMIN  ✓1 ~1 ✗10

---- SUMMARY ----
[+] owned=1   [~] admin=1   [-] fail=10   [.] error=0
  • owned.txt — alvos com RCE (shell URL)
  • admins.txt — admins criados sem sink de RCE (credenciais)
  • exploit_log.txt — detalhe por alvo
  • results.csv — resumo (exit_code: 0=owned, 4=admin, 2=fail, 3=error)

⚙️ Features

  • UNION SQLi in-band + timing + X-WP-Total oracle
  • Admin pré-auth via oEmbed/changeset poisoning
  • Login escondido (WPS Hide Login whl_page via SQLi) + slugs comuns
  • Upload de plugin com nonce/ativação corretos + fallback INTO OUTFILE
  • Massa sem limite, paralelo por alvo, deadline anti-hang
  • owned/admins em tempo real

📁 File Structure

├── wp2shell.py       # exploit + detector
├── targets.txt       # alvos (uma URL por linha)
├── owned.txt         # RCE conseguido (auto-criado)
├── admins.txt        # admins criados (auto-criado)
└── README.md

⚠️ Disclaimer

╔══════════════════════════════════════════════════════════════════╗
║                        LEGAL DISCLAIMER                          ║
╠══════════════════════════════════════════════════════════════════╣
║  This tool is provided for EDUCATIONAL and AUTHORIZED           ║
║  SECURITY TESTING purposes only.                                ║
║  Only use on systems you own or have explicit permission.       ║
║  The author is NOT responsible for any misuse or damage.        ║
╚══════════════════════════════════════════════════════════════════╝

🛡️ Mitigation

  1. Atualize para 6.8.6 / 6.9.5 / 7.0.2 (ou superior)
  2. Bloqueie POST não autenticado em /wp-json/batch/v1 e /?rest_route=/batch/v1
  3. Audite wp-content/uploads/ e wp-content/plugins/ em busca de PHP suspeito

👤 Author

fl0ydsec (Floydroot)

GitHub Telegram

Security Research

About

WP2Shell - CVE-2026-63030 + CVE-2026-60137 WordPress Core pre-auth RCE mass exploit

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages