Rule Info
Name
WordPress Wp2shell REST Batch Endpoint Exploitation
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030,
CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint
via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe
through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is
active on the target.
Reference
Date
2026-07-19 00:00:00
Modified
None
Id
b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f
Tags
attack.initial-access attack.t1190 detection.emerging-threats cve.2026-63030 cve.2026-60137
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6155 from @swachchhanda000 - Add WordPress Wp2shell Detections
2026-07-20
