Skip to content

new module request WordPress CVE-2026-63030 (wp2shell) #1638

Description

@securestep9

This module should be using the the /wp-json/batch/v1 route (and rest_route=/batch/v1) rather than rely on version detection (we already have a wordpress_version_scan module). This is a CISA KEV CVE: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions