What happened
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Affected versions
Core: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · Icex0/wp2shell-pocwp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chainRCEPython★ 757⑂ 172Code indexedUpdated 26 Aug 2026Tags: cve-2026-63030, wp2shell, wp2shell-pocIcex02026-07-17CandidateCVE-Intel · attackercan/wp2shell-poc2CVE-2026-63030Exploit★ 7⑂ 4Updated 25 Aug 2026attackercan2026-07-17CandidateCVE-Intel · 4minx/CVE-2026-63030CVE-2026-63030 (wp2shell) POC.PoCPython★ 10⑂ 2Code indexedUpdated 25 Aug 20264minx2026-07-18CandidateCVE-Intel · sowarma/wp2shell-PoCCVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-conceptRCEPython★ 914⑂ 215Code indexedUpdated 25 Aug 2026Tags: cve, cve-2026-60137, cve-2026-63030, data-analysis, wp2shell, wp2shell-pocsowarma2026-08-05CandidateCVE-Intel · dinosn/wp2shell-labNon-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1InjectionPython★ 59⑂ 21Code indexedUpdated 25 Aug 2026Tags: cve-2026-60137, cve-2026-63030, security, sql-injection, vulnerability-lab, wordpress, wp2shelldinosn2026-07-18CandidateCVE-Intel · Lutfifakee-Project/wp2shellwp2shell - WordPress CVE-2026-63030 Exploit & ScannerRCEPython★ 7⑂ 3Code indexedUpdated 24 Aug 2026Tags: cve-2026-63030, exploit, python, rce, security-tools, sql-injection, unauthenticated, unauthenticated-rceLutfifakee-Project2026-07-18CandidateCVE-Intel · ZephrFish/wp2shell-scannerCVE-2026-63030, CVE-2026-60137, wp2shell scannerExploitPython★ 55⑂ 11Code indexedUpdated 23 Aug 2026ZephrFish2026-07-17CandidateCVE-Intel · InstaWP/wp2shell-scanDetect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by defaultExploitShell★ 5⑂ 0Code indexedUpdated 22 Aug 2026InstaWP2026-07-19CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.