WordPress Wp2shell REST Batch Endpoint Exploitation

Rule Info

Name
WordPress Wp2shell REST Batch Endpoint Exploitation
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
Date
2026-07-19 00:00:00
Modified
None
Id
b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f
Tags
attack.initial-access attack.t1190 detection.emerging-threats cve.2026-63030 cve.2026-60137
Type
Community Rule

Rule History

Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6155 from @swachchhanda000 - Add WordPress Wp2shell Detections
2026-07-20