ThreatMon
WP2Shell Vulnerability Check
Check whether a public WordPress site is exposed to the WP2Shell vulnerability (CVE-2026-63030 / CVE-2026-60137). Enter a site URL to see whether it's vulnerable, affected by version, or clear.
6.8.0-7.0.1
Affected Versions
2
CVEs Chained
Pre-Auth
Access Required
Read-only
Detection Method
Free
No Account Needed
#Wp2Shell#PreAuthRCE#CVE-2026-63030
Action Center
What You Need to Know
Understand the Check
WP2Shell Vulnerability Check tests a WordPress site for CVE-2026-63030 (a REST /batch/v1 route-confusion bug) combined with CVE-2026-60137 (a WP_Query::author__not_in SQL injection). The full chain is actively testable on WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1; 6.8.0-6.8.5 carries the underlying SQL injection alone and is graded as affected even though the active check can't fire on that branch.
The check is detection-only: it confirms the injection with a timing differential alone. It never reads database contents, creates users, uploads files, or executes commands on the target.
Why It Matters
Left unpatched, this chain allows a fully unauthenticated attacker to:
Confirm the SQL injection with no credentials
Escalate to arbitrary administrator account creation
Upload a plugin and execute commands on the server
Fully compromise the site with no prior access
Take Action
ThreatMon recommends:
Updating WordPress to the latest patched version immediately
Auditing recently created administrator accounts
Reviewing installed/active plugins for anything unrecognized
Restricting access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the edge until patched
ThreatMon Intelligence
ThreatMon's platform extends this check into continuous monitoring, so newly disclosed WordPress CVEs are caught across your assets before they're exploited. Our intelligence surfaces:
Continuous CVE and exposure monitoring
Asset-wide vulnerability correlation
Actionable, prioritized remediation guidance
Read ThreatMon Threat Intelligence