Sergio adf12ec0cd USE IT RESPONSIBLY
add an IoC ish for some of the malicious users. I know this isn't very robust, it's just slightly for lazy people.
2026-07-18 18:59:28 +03:00
2026-07-18 18:59:28 +03:00

wp2shell PoC

The first ever poc of the pre-auth timing-based SQL injection PoC for the WordPress REST API batch-route confusion chain (CVE-2026-63030 + CVE-2026-60137)

Achieved command execution, without just trying to crack the admins password.

Affected: WordPress 6.9.06.9.4 and 7.0.07.0.1. Fixed in 6.9.5 and 7.0.2.

python3 poc.py https://target.example
python3 poc.py https://target.example 'SELECT DATABASE()'
python3 poc.py https://target.example -c "echo "you got pwned" > /tmp/pwned.txt && id"

Research: Searchlight Cyber · Aikido · Aikido Intel · WordPress

Disclaimer: This proof of concept is provided solely for authorized educational, security research, and incident response purposes; meaning, use it only on systems you own or have explicit permission to test.

S
Description
Automated archival mirror of github.com/sergiointel/wp2shell-poc
Readme 35 KiB
Languages
Python 100%