~/en/research $ cat wp2shell.md

WP2Shell Checker

CVE-2026-60137 CVE-2026-63030 CVSS 9.8 · WPScan Python 3 with no dependencies Read-only

Read-only script that identifies the WordPress version a site publishes and compares it against the version ranges affected by CVE-2026-60137 (SQL injection in WP_Query through the author__not_in parameter) and CVE-2026-63030 (path confusion in the REST API batch endpoint). It returns potentially affected, not affected or not determinable; it does not touch the site and installs no dependencies.

~/contactreply < 24 business hours · es / en

you@nullsector:~$ mail miguel

[email protected]

Collaborations, talks, press or research: write to me.

Need a pentest or a vulnerability assessment? Request it at Xpectra.ai ↗