Listen to this Post
CVE-2026-63030, widely known as the WP2Shell vulnerability, represents a critical security flaw residing within WordPress Core.
It enables unauthenticated remote code execution by chaining a severe REST API batch route confusion bug with a SQL injection defect.
The attack begins by targeting the WordPress REST API batch processing endpoint located at /wp-json/batch/v1.
An attacker sends a specially crafted batch request containing multiple sub-requests designed to trigger parsing errors.
During the execution phase, the WordPress batch processor handles validation and request routing across separate internal loops.
When the `wp_parse_url` function encounters a malformed URL path within one of the sub-requests, it generates a processing exception.
This exception correctly records an error in the validation tracking array but fails to synchronize properly with the matched handler array.
Consequently, an array desynchronization occurs, causing subsequent sub-requests in the batch payload to inherit incorrect routing handlers.
This routing confusion bypasses standard authentication checks and method restrictions enforced by the WordPress REST API framework.
Once the request context is corrupted, attackers exploit a secondary vulnerability designated as CVE-2026-60137.
CVE-2026-60137 is a SQL injection flaw located inside the `author__not_in` parameter handling of the `WP_Query` class.
Normally, input parameters passed to `WP_Query` are strictly sanitized, cast to integers, or prepared using safe database drivers.
However, because the batch router desynchronization bypasses normal parameter sanitization filters, raw malicious strings are processed.
The attacker supplies an injected string containing SQL commands directly into the vulnerable parameter vector.
This allows the execution of arbitrary SQL statements, granting unauthorized read access to sensitive database tables like wp_users.
By manipulating the database query results, the attacker constructs forged internal WordPress post objects in application memory.
These forged objects create an impossible state, such as a self-referencing parent post loop that triggers recursive save routines.
During these nested save operations, WordPress processes a Customizer changeset that momentarily assumes an administrator user ID.
Leveraging this temporary administrative identity context, the attacker executes a secondary recursive REST API call.
This nested request allows the unauthenticated attacker to programmatically create a rogue administrator account on the target site.
With administrative credentials successfully established, the attacker uploads a malicious plugin containing a PHP web shell.
Activating the plugin grants complete, arbitrary remote command execution capabilities over the underlying server infrastructure.
The entire exploit chain requires zero user interaction and impacts millions of default WordPress installations globally.
DailyCVE Form:
Platform: WordPress
Version: 6.9.x
Vulnerability: SQLi-RCE
Severity: Critical
date: July 2026
Prediction: Patched now
What Undercode Say
Check endpoint status and batch route routing behavior
curl -X POST "https://target.tld/wp-json/batch/v1" \
-H "Content-Type: application/json" \
-d '{"requests": [{"path": "/wp-v2/posts?author__not_in=1"}]}'
Run exploit script check against target instance
python3 wp2shell.py check --target https://target.tld
Exploit: (Educational Purposes!)
import requests
def exploit_wp2shell(target_url):
batch_endpoint = f"{target_url}/wp-json/batch/v1"
payload = {
"requests": [
{"path": "/malformed-path-trigger", "method": "POST"},
{"path": "/wp/v2/posts?author__not_in=1) UNION SELECT ...", "method": "GET"}
]
}
response = requests.post(batch_endpoint, json=payload)
return response.status_code, response.text
Protection: from this CVE
Upgrade WordPress core immediately to version 6.9.5 or 7.0.2 to receive official patches.
Restrict or block public access to the `/wp-json/batch/v1` REST API batch endpoint using a Web Application Firewall (WAF).
Disable anonymous access to the WordPress REST API entirely via security plugins if batch processing is not required.
Monitor server access logs and database general query logs for anomalous batch requests containing unescaped parameters.
Conduct routine audits of the `wp_users` table to detect unauthorized or newly provisioned administrator accounts.
Impact:
Complete compromise of the underlying web server infrastructure via arbitrary remote code execution (RCE).
Full database extraction, including sensitive user credentials, password hashes, and session tokens.
Persistent backdoor access established through uploaded malicious plugins or deployed PHP web shells.
Total loss of confidentiality, integrity, and availability for affected WordPress deployments worldwide.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

