Actively exploited flaw

WP2SHELL — Is your WordPress site at risk?

A critical WordPress core flaw lets an attacker take over a site remotely, without authentication — and web shells are already being deployed en masse. Check for free whether your site exposes a vulnerable version, without ever attacking it.

  • Free
  • Non-intrusive
  • No install
  • Verdict on screen and by email

Test your site

The address is used to create the free account and send the result. Never resold.

How it works

  1. 1

    Prove you own the domain

    A single DNS TXT record: the test only runs on a domain you own — never on someone else’s site.

  2. 2

    Non-intrusive diagnostic

    The test reads the publicly exposed WordPress version and whether the “batch” endpoint is present. No exploit payload is ever sent, nothing is changed.

  3. 3

    Your verdict, on screen and by email

    A clear verdict — at risk or not —, the evidence gathered and the steps to fix it.

What a vulnerable site risks

Full server takeover

Remote code execution without a password: the attacker becomes administrator of the server.

Data theft and defacement

Customer data, credentials and confidential content exposed; pages replaced, reputation damaged.

Persistent web shell and ransom

A web shell opens lasting access to the server: site lockout, extortion, pivoting to your other systems.

What it is

The chain combines an SQL injection (CVE-2026-60137) and code execution (CVE-2026-63030) through WordPress’s REST “batch” endpoint (/wp-json/batch/v1). It allows full server takeover without authentication. Web shells have been deployed en masse since the exploit code was published.

Affected versionsWordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. Fixed in 6.9.5 and 7.0.2.

How the test works

The test is a non-intrusive diagnostic. It reads the publicly exposed WordPress version (generator tag, RSS feed, readme, REST API) and observes whether the “batch” endpoint is present. It never sends an exploit payload. An “at risk” result flags an exposed version, not proof of exploitability.

Frequently asked questions

Does the test put your site at risk?
No. It is a non-intrusive diagnostic: it reads the publicly exposed WordPress version and checks whether the REST “batch” endpoint is present, without ever sending an exploit payload or changing anything.
Why is domain ownership verification required?
The test only runs on a domain whose ownership is proven by a DNS TXT record, and with explicit consent — that is what guarantees no third-party site is ever tested.
What should be done if your site is at risk?
Update WordPress to 6.9.5 or 7.0.2, or, in the meantime, block the /wp-json/batch/v1 endpoint at the web application firewall.

Don’t stay in the dark

Test my site now

Free, non-intrusive, no install — the test doesn’t touch your site.