{"repo":"dinosn/wp2shell-lab","free":true,"listed":false,"github":"https://github.com/dinosn/wp2shell-lab","clone":"git clone https://github.com/dinosn/wp2shell-lab.git","description":"Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1","language":"Python","stars":55,"topics":["security","sql-injection","vulnerability-lab","wordpress","wp2shell","cve-2026-60137","cve-2026-63030"],"license":"MIT","category":"security-tools","readme_excerpt":"wp2shell lab & detector + pre-auth RCE PoC A self-contained lab, non-destructive detector , and full pre-auth RCE proof-of-concept for wp2shell — the pre-authentication vulnerability chain in WordPress core: CVE Component Class CVSS ----- ----------- ------- ------ CVE-2026-60137 WP Query::author not in SQL injection (CWE-89) 9.1 CVE-2026-63030 REST /batch/v1 route confusion interpretation conflict (CWE-436) → chains to RCE 7.5 Affected: WordPress core 6.9.0–6.9.4 and 7.0.0–7.0.1 (the SQLi sink alone also affects 6.8.0–6.8.5). Fixed in 6.8.6 / 6.9.5 / 7.0.2. Reported by Adam Kues (Assetnote / Searchlight Cyber); SQLi also credited to TF1T, dtro, haongo. Stock-default RCE chain (oEmbed → changeset → re-entry) by Mustafa Can İPEKÇİ (nukedx). Update first. WordPress shipped forced auto-updates for this. This repo exists to help you verify your own estate is patched and to understand the bug — not to attack anyone. See SECURITY.md. --- What it actually is The always-true primitive is an unauthenticated, no-plugin, stock-core SQL injection giving full database read (admin password hashes, everything in wp options / wp users ). That alone earns the 9.1 and immediate patching. The RCE is real and works on stock-default WordPress — no FILE privilege, no persistent object cache, no plugins, no misconfigurations required. The chain uses the read-only SQLi as a row-forgery primitive ( UNION ALL SELECT injects fake wp posts rows), then leverages WordPress's own content-rendering pipeline","default_branch":null,"files":null,"tree":[],"storefront":"/r/dinosn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dinosn/wp2shell-lab/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}