← volver
CVE-2026-63030criticalbajo ataqueCWE-436

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

100Vexday Risk Score

Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.

ssvc Actcvss 9.8epss 39%
de la publicación al arma0 días
Publicada en NVD17 jul
1ª PoC17 jul
CISA KEV+4d
probabilidad de explotación
39%top 2% de las CVE
explotación observada
CISA + VulnCheck
98 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2026-07-24

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

En resumen

Versiones de WordPress anteriores a 6.9.5 y 7.0.2 tienen un defecto en su API REST que, combinado con otra vulnerabilidad de SQL Injection, permite que los atacantes ejecuten código malicioso en el sitio.

Detalle técnico

La vulnerabilidad explota confusión de rutas en el endpoint batch de la REST API combinado con inyección SQL a través del parámetro author__not_in en WP_Query para lograr ejecución arbitraria de código. Requiere acceso de red al endpoint REST API de WordPress; los atacantes pueden eludir restricciones e inyectar comandos SQL que conducen a RCE.

Resumen generado y traducido por IA a partir de la descripción oficial.
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
WordPress · WordPress
PoCs públicas encontradas98
githubgithub.com/Icex0/wp2shell-poc488githubgithub.com/0xsha/wp2shell59githubgithub.com/dinosn/wp2shell-lab37githubgithub.com/ZephrFish/wp2shell-scanner23githubgithub.com/47Cid/wp2shell-lab13githubgithub.com/NULL200OK/WP2Shell10githubgithub.com/4minx/CVE-2026-630308githubgithub.com/bahartanir/wp2shell-scanner7githubgithub.com/mcipekci/wp2shell7githubgithub.com/ekomsSavior/wp2shell7githubgithub.com/ikow/wp2shell7githubgithub.com/mhtsec/CVE-2026-630307githubgithub.com/attackercan/wp2shell-poc26githubgithub.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t5githubgithub.com/own2pwn-fr/wp2shell-detect5githubgithub.com/securelayer7/WordPresShell5githubgithub.com/Senanfurkan/wordpress-cve-2026-630304githubgithub.com/mverschu/CVE-2026-630304githubgithub.com/fullhunt/wp2shell-scan4githubgithub.com/Lutfifakee-Project/wp2shell4githubgithub.com/OffByOn3/CVE-2026-63030-Wp2Shell4githubgithub.com/GhostInExile/CVE-2026-63030-Wp2Shell4githubgithub.com/JohenLastGen-JLG/wp2shell2githubgithub.com/InstaWP/wp2shell-scan2githubgithub.com/ebrasha/abdal-cve-2026-630302githubgithub.com/0xWhoknows/wp2shell1githubgithub.com/gbrsh/CVE-2026-630301githubgithub.com/4B3R4M4-607D/CVE-2026-63030-POC1githubgithub.com/Crypto-Cat/wp2shell1githubgithub.com/administrator-01001/CVE-2026-630301githubgithub.com/joaovicdev/EXPLOIT-CVE-2026-630301githubgithub.com/0xjessie21/wp2shell-checker1githubgithub.com/SentinelXofficial/sxwp2shell1githubgithub.com/0xBlackash/CVE-2026-630301githubgithub.com/lucifer0xf/wp2shell-Wordpress-TOWN1githubgithub.com/Ch4120N/CVE-2026-630301githubgithub.com/Lukols-Dev/wp-cve-2026-63030-check0githubgithub.com/tcyph3r/wp2shell-cve-2026-63030-root-cause0githubgithub.com/kulichr/wp2shell0githubgithub.com/CybersecSpirit/CVE-2026-630300githubgithub.com/0xh7ml/CVE-2026-630300githubgithub.com/mrx-arafat/CVE-2026-63030-POC0githubgithub.com/zi3lak/wp2shell_scanner0githubgithub.com/ChiefYoru/CVE-2026-63030_PoC0githubgithub.com/c0gnit00/Wp2Shell0githubgithub.com/TomorrowX6/CVE-2026-63030-poc0githubgithub.com/eyesecurity/wp2shell-compromise-scanner-plugin0githubgithub.com/hidden-investigations/wp2shell-scanner0githubgithub.com/ananay/wp2shell-lab0githubgithub.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-630300githubgithub.com/vulnquest58/PressVector0githubgithub.com/ZenithGenius/wordpress-batch-rce-lab0githubgithub.com/wn-iqbal/wp2shell0githubgithub.com/ASYquan/wp2shell-cf-WAF-bypass0githubgithub.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC0githubgithub.com/Adrees-Basheer/wp2shell-vulnerability-scanner0githubgithub.com/raphy76/wp2shell-poc-fulljs0githubgithub.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc0vulncheckvulncheck.com/xdb/8dbd04a4715cno verificadovulncheckvulncheck.com/xdb/8c29f2e09796no verificadovulncheckvulncheck.com/xdb/ef1c955d04acno verificadovulncheckvulncheck.com/xdb/0e155f021cb0no verificadovulncheckvulncheck.com/xdb/9dca80693885no verificadovulncheckvulncheck.com/xdb/c229388b4517no verificadovulncheckvulncheck.com/xdb/510f91fde2edno verificadovulncheckvulncheck.com/xdb/8e380a2c7e7eno verificadovulncheckvulncheck.com/xdb/2c22ab77cd0ano verificadovulncheckvulncheck.com/xdb/61034f32533ano verificadovulncheckvulncheck.com/xdb/3ceb02ef656ano verificadovulncheckvulncheck.com/xdb/16827e184acbno verificadovulncheckvulncheck.com/xdb/7d95ef261acdno verificadovulncheckvulncheck.com/xdb/3c96356b1386no verificadovulncheckvulncheck.com/xdb/10808d9e73c0no verificadovulncheckvulncheck.com/xdb/d747655380f6no verificadovulncheckvulncheck.com/xdb/7babea7a47ddno verificadovulncheckvulncheck.com/xdb/94e81da06661no verificadovulncheckvulncheck.com/xdb/b53ae1b8dd32no verificadovulncheckvulncheck.com/xdb/5a4dfe2f0910no verificadovulncheckvulncheck.com/xdb/b733ce85b287no verificadovulncheckvulncheck.com/xdb/b4b379bb0c8fno verificadovulncheckvulncheck.com/xdb/eab18983fb0cno verificadovulncheckvulncheck.com/xdb/9549cbf43f25no verificadovulncheckvulncheck.com/xdb/90adf004a285no verificadovulncheckvulncheck.com/xdb/afadcf0f8e23no verificadovulncheckvulncheck.com/xdb/771dab10adc6no verificadovulncheckvulncheck.com/xdb/94d096ef3535no verificadovulncheckvulncheck.com/xdb/7bb16a1ea945no verificadovulncheckvulncheck.com/xdb/355109b3ef07no verificadovulncheckvulncheck.com/xdb/a075ba6e6e67no verificadovulncheckvulncheck.com/xdb/03aa0310e804no verificadovulncheckvulncheck.com/xdb/215f44b8a7b9no verificadovulncheckvulncheck.com/xdb/5908e23870ceno verificadovulncheckvulncheck.com/xdb/e32cda881d69no verificadovulncheckvulncheck.com/xdb/aad1b5a41723no verificadovulncheckvulncheck.com/xdb/e7433f2d580cno verificadovulncheckvulncheck.com/xdb/98c3d3a11ea8no verificadovulncheckvulncheck.com/xdb/7eab346d6260no verificadovulncheckvulncheck.com/xdb/1460088472dbno verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.