Skip to content
Exploit for Interpretation Conflict in Wordpress

Exploit for Interpretation Conflict in Wordpress

Sploitus • September 27, 2026

| `docker-compose.yml` | Compose file that deploys a self-contained vulnerable WordPress 6.9.4 + MySQL 8.0 environment |

| `cve-2026-63030_cve-2026-60137_poc.py` | Python 3 proof of concept script that performs unauthenticated time-based blind SQL injection via the WP2Shell chain |

These files are provided as part of a technical exercise submission for the Junior Offensive Security Engineer position at Secuna. They are intended for use against the isolated lab environment described in this README only.

WP2Shell is a critical pre-authentication vulnerability chain in WordPress Core. It combines two independent flaws:

- **CVE-2026-63030** causes the REST API batch endpoint (`/?rest_route=/batch/v1`) to desynchronize its internal validation and handler-match arrays when a sub-request path fails to parse. This allows subsequent sub-requests to be dispatched under incorrect handlers and permission contexts, effectively bypassing authentication and schema validation.

- **CVE-2026-60137** is a SQL injection vulnerability in `WP_Query::get_posts()`. The `author__not_in` parameter is only sanitized via `absint()` when it arrives as an array. When a raw string reaches the parameter, sanitization is skipped and the value is concatenated directly into the SQL `NOT IN` clause.

This proof of concept demonstrates the SQL injection stage of the chain. It does not implement the full WP2Shell escalation path to remote code execution.

The following must be installed on your system before proceeding. This environment was built and validated on **Kali Linux**. Native Linux or a Linux virtual machine is strongly recommended. Docker on Windows via Docker Desktop behaves differently from native Linux Docker and may cause MySQL initialization failures or inconsistent batch endpoint behavior.

- **Docker** — `sudo apt install -y docker.io`

- **Docker Compose** — `sudo apt install -y docker-compose`

- **Python 3** — included by default on Kali Linux

- **pip** — `sudo apt install -y python3-pip`

- **requests (Python library)** — `pip install requests`

Allocate at minimum **4 GB of RAM** and **2 CPU cores** to your virtual machine if running in a VM. Time-based blind injection introduces deliberate sleep delays per request, and an under-resourced machine may produce inconsistent timing results.

Save both files from this folder into the same working directory on your machine:

# place docker-compose.yml and cve-2026-63030_cve-2026-60137_poc.py here

-rw-rw-r-- 1 user user XXX docker-compose.yml

-rw-rw-r-- 1 user user XXX cve-2026-63030_cve-2026-60137_poc.py

### Step 2 — Start the vulnerable environment

From the working directory, bring up both containers:

This pulls `mysql:8.0` and `wordpress:6.9.4-apache` and starts both containers in detached mode. Wait approximately **60 to 90 seconds** for the MySQL container to finish initializing before proceeding. Monitor the container status with:

Both containers must show a status of `Up` before proceeding. If the `wordpress` container shows `Exit` or `Restarting`, MySQL has not finished initializing. Wait and retry.

### Step 3 — Complete the WordPress installation

Navigate to ` in a browser. WordPress will present the standard five-minute installation wizard. Complete it by providing:

- **Username** — any value (note it down for validation purposes only)

- **Password** — any value (note it down for validation purposes only)

The WP2Shell exploit chain is entirely unauthenticated. These credentials are only needed to verify the instance state after setup and are not used by the exploit script.

### Step 4 — Verify the vulnerable version

curl -sL " | grep -i 'generator'

### Step 5 — Verify the batch endpoint is reachable

curl -s -X POST -o /dev/null -w "HTTP %{http_code}\n" \

"

HTTP 400 means WordPress found the endpoint and rejected the empty request body. This confirms the endpoint is reachable. If you receive HTTP 404, navigate to **Settings → Permalinks** in the WordPress admin panel, select any option other than Plain, click Save Changes, and retry.

python3 cve-2026-63030_cve-2026-60137_poc.py -u

| `-u`, `--url` | Target WordPress base URL | Required |

| `-t`, `--threads` | Concurrent threads for character extraction | 10 |

| `--timeout` | HTTP request timeout in seconds | 30 |

python3 cve-2026-63030_cve-2026-60137_poc.py -u -t 15 --timeout 60

Increasing threads reduces extraction time for longer strings such as password hashes. A higher timeout is advisable on under-resourced virtual machines.

A successful run produces output in three phases:

----------------------------------------------------------------------

CVE-2026-63030 REST API Batch Route Confusion (CWE-436)

CVE-2026-60137 WP_Query SQL Injection via author__not_in (CWE-89)

----------------------------------------------------------------------

Affected : WordPress 6.9.0-6.9.4 / 7.0.0-7.0.1

----------------------------------------------------------------------

======================================================================

======================================================================

[*] TRUE condition: HTTP 207, Time: ~5.0s

[*] FALSE condition: HTTP 207, Time: ~0.08s

[*] Phase 2: Extracting Database Information

============================================================

============================================================

------------------------------------------------------------

ID Username Admin Password Hash

------------------------------------------------------------

1 admin YES $wp$2y$10$...

------------------------------------------------------------

[+] Results saved to: extracted_results.txt

All extracted data is also saved to `extracted_results.txt` in the working directory.

To independently verify the extracted password hash matches what is stored in the database, query the MySQL container directly:

docker exec -it wp2shell-lab-db-1 mysql -u root -prootpassword \

-e "USE wordpress; SELECT user_login, user_pass FROM wp_users WHERE user_login='admin';"

> Note: The container name (`wp2shell-lab-db-1`) may differ depending on your working directory name. Run `docker-compose ps` to confirm the exact container name for the `db` service.

**Phase 1 fails with `[-] SQLi not confirmed`**

Confirm the WordPress installation wizard was completed before running the script. Confirm the batch endpoint returns HTTP 400 (Step 5 above). Confirm both containers are in `Up` state via `docker-compose ps`. If containers are running but the endpoint still fails, restart with `docker-compose down && docker-compose up -d` and repeat Steps 3 through 5.

The `--timeout` value may be too low relative to your machine's performance. Restart with `--timeout 60`. Alternatively, the MySQL container may be under high load from test runs. Restart the environment and wait for full initialization before retrying.

WordPress permalinks are not enabled. Log into the admin panel at ` navigate to Settings → Permalinks, select any option other than Plain, and click Save Changes.

**Container name not found in docker exec**

Run `docker ps` to list all running containers and identify the correct name for the `db` service. Replace the container name in the `docker exec` command accordingly.

To stop and remove all containers, networks, and volumes created by this environment:

The `-v` flag removes the named volumes (`db_data` and `wp_data`), ensuring a clean state for subsequent runs.

This proof of concept and the vulnerable environment it targets are provided exclusively for the purpose of this technical exercise submission. Use of this script against any system other than the local Docker environment described in this README, without explicit written authorization from the system owner, is illegal and unethical.

The author assumes no responsibility for misuse of this material.

1. Bitdefender Business Insights — Technical Advisory: wp2shell

2. Symbiotic Security — Analysis of wp2shell

3. Cytidel — wp2shell: The Pre-Auth RCE Hiding in the Gap Between Two WordPress CVEs

4. Wordfence — wp2shell WordPress Exploit: Technical Analysis and Real Attack Data