
wp2shell (weekend to shell edition)
WordPress runs roughly 40% of the internet, so when a routine weekend dig into its REST API turned up a pre-auth path to full database compromise, we didn't get much sleep. In this write-up, we chain a batch-endpoint route confusion bug (CVE-2026-63030) with a SQL injection in WP_Query (CVE-2026-60137) to go from anonymous request to admin account, no cracked hashes required. Read the full article to see how we faked oEmbed cache entries, built a nav_menu_item privilege chain out of seven UNION queries, and landed a webshell without ever logging in.
- Published at
- Updated at


















