{"name":"wp2shell","repo":"manpisetsu/wp2shell","url":"https://midorreal.com/project/manpisetsu-wp2shell","repository":"https://github.com/manpisetsu/wp2shell","description":"CVE-2026-63030 + CVE-2026-60137 exploit RCE chain","facts":{"language":{"value":"Python","source":"https://github.com/manpisetsu/wp2shell","checked":"9 Oct 2026"},"releases":{"value":"0","source":"https://github.com/manpisetsu/wp2shell/releases","checked":"9 Oct 2026"},"contributors":{"value":"1","source":"https://github.com/manpisetsu/wp2shell/graphs/contributors","checked":"9 Oct 2026"},"archived":{"value":"no","source":"https://github.com/manpisetsu/wp2shell","checked":"9 Oct 2026"}},"stars":152.0,"writeup":{"what_it_is":"A proof-of-concept exploit demonstrating a pre-authentication remote code execution chain in WordPress Core. It combines CVE-2026-63030 (REST API batch route confusion) and CVE-2026-60137 (WP_Query SQL injection) to achieve unauthenticated WordPress compromise.","audience":"Security researchers, bug bounty hunters, WordPress administrators.","claims":[{"kind":"specific","claim":"Requires only Python 3.8 or later","excerpt":"To use this PoC, the only requirement is Python 3.8+.","status":"not_checked"}],"alternatives":[],"written_by":"AI, from the project's README","date":"2026-10-09"},"why_now":null,"owner_supplied":null,"score":{"verdict":"mid","hype":38,"reality":17,"gap":22,"momentum":null,"confidence":60,"version":"score-2.0","rule":"verdict-2.0","calculated_at":"2026-10-09T05:00:00+00:00","verdict_source":"rule"},"early_read":null,"changes":[{"date":"2026-10-07T16:45:25+00:00","text":"Repository created","source":"https://github.com/manpisetsu/wp2shell"}],"cite":"wp2shell is a GitHub project at https://github.com/manpisetsu/wp2shell written mainly in Python, described there as \"CVE-2026-63030 + CVE-2026-60137 exploit RCE chain\".","attribution":"Data from Mid or Real, https://midorreal.com/project/manpisetsu-wp2shell, checked 9 October 2026. Attribution with a link is required."}