WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Published 26 Aug 2026Updated 26 Aug 2026146 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

Affected versions

Core: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · Icex0/wp2shell-pocwp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chainRCEPython★ 757⑂ 172Code indexedUpdated 26 Aug 2026Tags: cve-2026-63030, wp2shell, wp2shell-pocIcex02026-07-17CandidateCVE-Intel · attackercan/wp2shell-poc2CVE-2026-63030Exploit★ 7⑂ 4Updated 25 Aug 2026attackercan2026-07-17CandidateCVE-Intel · 4minx/CVE-2026-63030CVE-2026-63030 (wp2shell) POC.PoCPython★ 10⑂ 2Code indexedUpdated 25 Aug 20264minx2026-07-18CandidateCVE-Intel · sowarma/wp2shell-PoCCVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-conceptRCEPython★ 914⑂ 215Code indexedUpdated 25 Aug 2026Tags: cve, cve-2026-60137, cve-2026-63030, data-analysis, wp2shell, wp2shell-pocsowarma2026-08-05CandidateCVE-Intel · dinosn/wp2shell-labNon-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1InjectionPython★ 59⑂ 21Code indexedUpdated 25 Aug 2026Tags: cve-2026-60137, cve-2026-63030, security, sql-injection, vulnerability-lab, wordpress, wp2shelldinosn2026-07-18CandidateCVE-Intel · Lutfifakee-Project/wp2shellwp2shell - WordPress CVE-2026-63030 Exploit & ScannerRCEPython★ 7⑂ 3Code indexedUpdated 24 Aug 2026Tags: cve-2026-63030, exploit, python, rce, security-tools, sql-injection, unauthenticated, unauthenticated-rceLutfifakee-Project2026-07-18CandidateCVE-Intel · ZephrFish/wp2shell-scannerCVE-2026-63030, CVE-2026-60137, wp2shell scannerExploitPython★ 55⑂ 11Code indexedUpdated 23 Aug 2026ZephrFish2026-07-17CandidateCVE-Intel · InstaWP/wp2shell-scanDetect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by defaultExploitShell★ 5⑂ 0Code indexedUpdated 22 Aug 2026InstaWP2026-07-19Candidate