[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDitNtkmMFdMWaWd-Mrux6uo9F36jn_ib021GQPbh354":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"eyesecurity","https:\u002F\u002Fprofiles.wordpress.org\u002Feyesecurity\u002F",1,200,100,30,94,"2026-08-29T07:14:26.120Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":8,"num_ratings":6,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":32,"unpatched_count":32,"last_vuln_date":33,"fetched_at":34},"compromise-scanner-for-wp2shell","Compromise Scanner for wp2shell","1.1.0","\u003Cp>Compromise Scanner for wp2shell is a \u003Cstrong>read-only\u003C\u002Fstrong> forensic scanner for the WordPress core exploit chain publicly tracked as \u003Cstrong>CVE-2026-63030\u003C\u002Fstrong> (REST batch route confusion) and \u003Cstrong>CVE-2026-60137\u003C\u002Fstrong> (\u003Ccode>author__not_in\u003C\u002Fcode> SQL injection), widely referred to as \u003Cem>wp2shell\u003C\u002Fem>.\u003C\u002Fp>\n\u003Cp>It inspects the database and the plugin directory for artifacts the exploit leaves behind — even when the attacker cleaned up afterwards — and presents a scored verdict on its own admin screen. It does \u003Cstrong>not\u003C\u002Fstrong> change anything on your site, and it does \u003Cstrong>not\u003C\u002Fstrong> fix the vulnerability. To close the hole, update WordPress core.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What it checks (each weighted by severity):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>oembed_cache\u003C\u002Fcode> entries that loop back to your own site, that number exactly three, or that were created around the disclosure date (the exploit uses oembed rendering as a write primitive).\u003C\u002Fli>\n\u003Cli>Object-graph artifacts: posts with implausibly high parent IDs, known proof-of-concept titles\u002Fslugs, and \u003Ccode>customize_changeset\u003C\u002Fcode> entries created since disclosure.\u003C\u002Fli>\n\u003Cli>Account artifacts: the \u003Ccode>wp2_\u003C\u002Fcode> login prefix and \u003Ccode>@wp2shell.invalid\u003C\u002Fcode> email used by public exploit code, and non-founder administrator accounts created since disclosure.\u003C\u002Fli>\n\u003Cli>Deleted-admin traces: orphaned user metadata and gaps in the user-ID sequence (create-then-delete).\u003C\u002Fli>\n\u003Cli>Webshell plugin files or directories matching \u003Ccode>wp2shell_*\u003C\u002Fcode>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>How it reads:\u003C\u002Fstrong> the weighted score maps to \u003Cem>No indicators\u003C\u002Fem> (under 25), \u003Cem>Some indicators\u003C\u002Fem> (25–49), or \u003Cem>Multiple indicators\u003C\u002Fem> (50+). Each check is shown with its severity and detail so you can verify it yourself. Matched checks are not proof of a breach.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Export:\u003C\u002Fstrong> the \u003Cstrong>Export report (.zip)\u003C\u002Fstrong> button downloads a zip archive for record-keeping or to hand to an investigator. Because the exploit hides its SQL injection and pre-auth admin creation inside a REST batch request body — which web servers do not log — the database artifacts are the primary evidence, so the archive includes the raw rows a human needs to review: the report as JSON and plain text, the relevant \u003Ccode>oembed_cache\u003C\u002Fcode>, \u003Ccode>customize_changeset\u003C\u002Fcode>, suspect posts, suspect users (exploit-default logins\u002Femails and new administrators; never password hashes), orphaned usermeta and changed plugin files, plus \u003Ccode>LOG-COLLECTION-GUIDE.txt\u003C\u002Fcode> listing the server-side logs to gather by hand (the plugin cannot read those itself). If the server lacks the PHP zip extension, a single JSON file with the same data is downloaded instead. The export is generated on the fly and stores nothing on the site.\u003C\u002Fp>\n\u003Cp>This is a focused, single-purpose tool. It is best-effort: matched checks are not proof of a breach on their own, and an all-clear result is not a guarantee. Do not act on this quick check alone — verify matched checks with your webmaster, consider a proper investigation (server and access logs, file integrity) if anything is unexplained, and treat reinstalling WordPress as a last resort. It complements, and does not replace, updating core and a professional investigation.\u003C\u002Fp>\n","Read-only forensic scanner for the WordPress core exploit chain CVE-2026-63030 \u002F CVE-2026-60137 (wp2shell). Reports a scored verdict; changes nothing.",842,"2026-07-20T08:53:00.000Z","7.0.2","5.6","7.2",[25,26,27,28,29],"forensics","malware","security","vulnerability","wp2shell","https:\u002F\u002Fgithub.com\u002Feyesecurity\u002Fwp2shell-compromise-scanner-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcompromise-scanner-for-wp2shell.1.1.0.zip",0,null,"2026-07-22T17:31:50.256Z"]