COLCERT issued alert 20260928-120 warning of exploitation associated with Kapibala_wp2shell_WordPress. Reporting identifies the alleged issue as CVE-2026-63030, a potential remote-code-execution path in WordPress core that requires no vulnerable plugin and targets the REST API batch endpoint at /wp-json/batch/v1/.
The reported technique uses malformed URLs to desynchronize batch-request validation from the callbacks selected for execution, potentially allowing a callback to execute after validation fails. Organizations running WordPress should urgently determine whether their deployments expose the batch REST endpoint, review web and application logs for anomalous requests to /wp-json/batch/v1/, and watch for unauthorized files or web shells in WordPress web roots; the available notices do not specify affected versions, confirmed indicators, or an official remediation.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
COLCERT AL published alert 20260928-120 concerning exploitation identified as “Kapibala_wp2shell_WordPress.” The supplied notice associates the activity with WordPress but provides no CVE, affected versions, indicators, attribution, or mitigation details.
A campaign active from June through September 2026 was attributed by CSIRT Panamá to Red Heron, which allegedly exploited WordPress flaws including CVE-2026-63030 and CVE-2026-60137 to compromise a Western government organization and exfiltrate more than 18,566 records. The report also documented exploitation of ZyXEL GS1900 switches and other exposed platforms, affecting 49 WordPress organizations in 29 countries and 996 ZyXEL devices in 48 countries.
An article described “wp2shell” as a plugin-free WordPress exploitation technique allegedly targeting CVE-2026-63030 in REST API batch processing at the /wp-json/batch/v1/ endpoint. It claimed malformed URLs could desynchronize validation and callback-selection arrays, allowing execution of a callback associated with another request.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecolcert.gov.co
Open sourcecert.pa
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.