wp2shell Check
wp2shell

Is your WordPress site exposed to wp2shell?

Enter a domain. We check for the batch-route confusion SQL injection (CVE-2026-63030 / CVE-2026-60137) — in seconds. No signup. No agent.

Passive check — nothing beyond a normal page fetch.

wp2shell Check is a free tool by SOCRadar that determines whether a WordPress site is exposed to the batch-route confusion SQL injection chain (CVE-2026-63030 / CVE-2026-60137). Enter a domain to check its exposure — no account required.

Route Confusion Check

Confirms the REST /batch/v1 route confusion (CVE-2026-63030) with a non-timing structural probe.

SQLi Timing Differential

Sends a fast and slow injection through the batch handler and measures the delay to confirm the SQLi.

Version Fingerprinting

Detects the running WordPress version and matches it against the known affected ranges.

Instant Results

No signup, no agent to install — results in seconds, right on this page.

F.A.Q.

Find answers to common questions about wp2shell and this checker