Files
sergiointel-wp2shell-poc/README.md
T
Sergio c4c8ac5ff8 Add README for wp2shell PoC
Add README for wp2shell PoC detailing SQL injection vulnerability and usage instructions.
2026-07-18 01:17:00 +03:00

922 B
Raw Blame History

wp2shell PoC

The first ever poc of the pre-auth timing-based SQL injection PoC for the WordPress REST API batch-route confusion chain (CVE-2026-63030 + CVE-2026-60137); still working on command exec

Affected: WordPress 6.9.06.9.4 and 7.0.07.0.1. Fixed in 6.9.5 and 7.0.2.

python3 poc.py https://target.example
python3 poc.py https://target.example 'SELECT DATABASE()'

Research: Searchlight Cyber · Aikido · Aikido Intel · WordPress