TGViewer
cKure Red cKure Red @ckured · 2.77K subscribers
Post #757 2.09K
✅CVE-2026-63030: Unauthenticated SQL injection in WordPress core chaining to RCE. No credentials, no configuration. One endpoint: POST /wp-json/batch/v1.

The REST batch endpoint builds two parallel arrays ($matches and $validation) that fall out of step when a sub-request path fails wp_parse_url(). A sub-request gets dispatched under a different handler's context. The PoC nests this route confusion twice: first to bypass the method allow-list, then to reach a blind SQL injection via author_exclude in WP_Query, which interpolates the value into SQL as a string.


The chain:
boolean/time-based blind SQLi → extract admin password hash → crack → plugin upload → command execution. Interactive shell included.

Affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Fixed in 6.9.5 and 7.0.2. Python 3.8+, zero dependencies.

Mitigation:
block /wp-json/batch/v1 and rest_route=/batch/v1 at the edge, or require auth via rest_pre_dispatch filter.


https://github.com/Icex0/wp2shell-poc
  • ❤ 1
More from @ckured
  1. Oct 3, 2026Update: Archivegenocide has now crossed 200,000 videos & images, which is almost triple wh…
  2. Sep 29, 2026📱 Telegram OSINT tactics
  3. Sep 26, 2026☁️ Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops…
  4. Sep 23, 2026Alleged Google Pixel 10 Zero Day at 2.5K USD only as chain included some n-days. An intere…
  5. Sep 18, 2026AliExpress spyware caught using side channel attack to compromise hardware.
  6. Sep 17, 2026😒 Claude Code was used to make missile guidance system for 9 months by Houthis using mult…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →