← voltar
CVE-2026-63030criticalsob ataqueCWE-436

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 9.8epss 39%
da publicação à arma0 dias
Publicada no NVD17 de jul.
1ª PoC17 de jul.
CISA KEV+4d
probabilidade de exploração
39%top 2% das CVEs
exploração observada
simCISA + VulnCheck
98 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2026-07-24

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Em resumo

Versões do WordPress anteriores a 6.9.5 e 7.0.2 possuem um problema na API REST que, combinado com outra falha de SQL Injection, permite que atacantes executem código malicioso no site.

Detalhe técnico

A vulnerabilidade explora confusão de rotas no endpoint batch da REST API em conjunto com injeção SQL via parâmetro author__not_in do WP_Query para alcançar execução de código arbitrário. Requer acesso à rede do endpoint REST API do WordPress; atacantes podem contornar restrições e injetar comandos SQL que levam a RCE.

Resumo gerado e traduzido por IA a partir da descrição oficial.
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
WordPress · WordPress
PoCs públicas encontradas98
githubgithub.com/Icex0/wp2shell-poc488githubgithub.com/0xsha/wp2shell59githubgithub.com/dinosn/wp2shell-lab37githubgithub.com/ZephrFish/wp2shell-scanner23githubgithub.com/47Cid/wp2shell-lab13githubgithub.com/NULL200OK/WP2Shell10githubgithub.com/4minx/CVE-2026-630308githubgithub.com/bahartanir/wp2shell-scanner7githubgithub.com/mcipekci/wp2shell7githubgithub.com/ekomsSavior/wp2shell7githubgithub.com/ikow/wp2shell7githubgithub.com/mhtsec/CVE-2026-630307githubgithub.com/attackercan/wp2shell-poc26githubgithub.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t5githubgithub.com/own2pwn-fr/wp2shell-detect5githubgithub.com/securelayer7/WordPresShell5githubgithub.com/Senanfurkan/wordpress-cve-2026-630304githubgithub.com/mverschu/CVE-2026-630304githubgithub.com/fullhunt/wp2shell-scan4githubgithub.com/Lutfifakee-Project/wp2shell4githubgithub.com/OffByOn3/CVE-2026-63030-Wp2Shell4githubgithub.com/GhostInExile/CVE-2026-63030-Wp2Shell4githubgithub.com/JohenLastGen-JLG/wp2shell2githubgithub.com/InstaWP/wp2shell-scan2githubgithub.com/ebrasha/abdal-cve-2026-630302githubgithub.com/0xWhoknows/wp2shell1githubgithub.com/gbrsh/CVE-2026-630301githubgithub.com/4B3R4M4-607D/CVE-2026-63030-POC1githubgithub.com/Crypto-Cat/wp2shell1githubgithub.com/administrator-01001/CVE-2026-630301githubgithub.com/joaovicdev/EXPLOIT-CVE-2026-630301githubgithub.com/0xjessie21/wp2shell-checker1githubgithub.com/SentinelXofficial/sxwp2shell1githubgithub.com/0xBlackash/CVE-2026-630301githubgithub.com/lucifer0xf/wp2shell-Wordpress-TOWN1githubgithub.com/Ch4120N/CVE-2026-630301githubgithub.com/Lukols-Dev/wp-cve-2026-63030-check0githubgithub.com/tcyph3r/wp2shell-cve-2026-63030-root-cause0githubgithub.com/kulichr/wp2shell0githubgithub.com/CybersecSpirit/CVE-2026-630300githubgithub.com/0xh7ml/CVE-2026-630300githubgithub.com/mrx-arafat/CVE-2026-63030-POC0githubgithub.com/zi3lak/wp2shell_scanner0githubgithub.com/ChiefYoru/CVE-2026-63030_PoC0githubgithub.com/c0gnit00/Wp2Shell0githubgithub.com/TomorrowX6/CVE-2026-63030-poc0githubgithub.com/eyesecurity/wp2shell-compromise-scanner-plugin0githubgithub.com/hidden-investigations/wp2shell-scanner0githubgithub.com/ananay/wp2shell-lab0githubgithub.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-630300githubgithub.com/vulnquest58/PressVector0githubgithub.com/ZenithGenius/wordpress-batch-rce-lab0githubgithub.com/wn-iqbal/wp2shell0githubgithub.com/ASYquan/wp2shell-cf-WAF-bypass0githubgithub.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC0githubgithub.com/Adrees-Basheer/wp2shell-vulnerability-scanner0githubgithub.com/raphy76/wp2shell-poc-fulljs0githubgithub.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc0vulncheckvulncheck.com/xdb/8dbd04a4715cnão verificadovulncheckvulncheck.com/xdb/8c29f2e09796não verificadovulncheckvulncheck.com/xdb/ef1c955d04acnão verificadovulncheckvulncheck.com/xdb/0e155f021cb0não verificadovulncheckvulncheck.com/xdb/9dca80693885não verificadovulncheckvulncheck.com/xdb/c229388b4517não verificadovulncheckvulncheck.com/xdb/510f91fde2ednão verificadovulncheckvulncheck.com/xdb/8e380a2c7e7enão verificadovulncheckvulncheck.com/xdb/2c22ab77cd0anão verificadovulncheckvulncheck.com/xdb/61034f32533anão verificadovulncheckvulncheck.com/xdb/3ceb02ef656anão verificadovulncheckvulncheck.com/xdb/16827e184acbnão verificadovulncheckvulncheck.com/xdb/7d95ef261acdnão verificadovulncheckvulncheck.com/xdb/3c96356b1386não verificadovulncheckvulncheck.com/xdb/10808d9e73c0não verificadovulncheckvulncheck.com/xdb/d747655380f6não verificadovulncheckvulncheck.com/xdb/7babea7a47ddnão verificadovulncheckvulncheck.com/xdb/94e81da06661não verificadovulncheckvulncheck.com/xdb/b53ae1b8dd32não verificadovulncheckvulncheck.com/xdb/5a4dfe2f0910não verificadovulncheckvulncheck.com/xdb/b733ce85b287não verificadovulncheckvulncheck.com/xdb/b4b379bb0c8fnão verificadovulncheckvulncheck.com/xdb/eab18983fb0cnão verificadovulncheckvulncheck.com/xdb/9549cbf43f25não verificadovulncheckvulncheck.com/xdb/90adf004a285não verificadovulncheckvulncheck.com/xdb/afadcf0f8e23não verificadovulncheckvulncheck.com/xdb/771dab10adc6não verificadovulncheckvulncheck.com/xdb/94d096ef3535não verificadovulncheckvulncheck.com/xdb/7bb16a1ea945não verificadovulncheckvulncheck.com/xdb/355109b3ef07não verificadovulncheckvulncheck.com/xdb/a075ba6e6e67não verificadovulncheckvulncheck.com/xdb/03aa0310e804não verificadovulncheckvulncheck.com/xdb/215f44b8a7b9não verificadovulncheckvulncheck.com/xdb/5908e23870cenão verificadovulncheckvulncheck.com/xdb/e32cda881d69não verificadovulncheckvulncheck.com/xdb/aad1b5a41723não verificadovulncheckvulncheck.com/xdb/e7433f2d580cnão verificadovulncheckvulncheck.com/xdb/98c3d3a11ea8não verificadovulncheckvulncheck.com/xdb/7eab346d6260não verificadovulncheckvulncheck.com/xdb/1460088472dbnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.