WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)
-
Updated
Jul 21, 2026 - Python
WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)
A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core
Critical Wordpress to Shell (unauthenticated)
Add a description, image, and links to the wp2shell-exploit topic page so that developers can more easily learn about it.
To associate your repository with the wp2shell-exploit topic, visit your repo's landing page and select "manage topics."