wp2shell - WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1 - Pre-Auth Batch-Route Confusion leading to SQL Injection CVE-2026-63030

Severity
EPSS Score
EPSS Percentile
Vulnerability description
Not available
Risk description
Not available
Exploit capabilities

Sniper can gain unauthenticated Remote Code Execution on the target system and extract multiple artefacts as evidence.

Recommendation
Not available
Codename
wp2shell
Detectable with
Network Scanner
Scan engine
Sniper
Cisa Kev
No
Exploitable with Sniper
Yes
CVE Published
Jul 10, 2026
Detection added at
Software Type
CMS
Vendor
WordPress
Product
WordPress

Detect this vulnerability now!

Check your clients' targets (or your own) for this vulnerability and thousands more! Get proof for validation with our ethical hacking toolkit.