PoC Published for CVE-2026-63030: wp2shell-Hestia-Scanner
July 27, 2026 · GitHub · Severity: CRITICAL
A proof-of-concept (PoC) scanner has been published on GitHub to detect indicators of wp2shell compromises (CVE-2026-63030 and CVE-2026-60137) on WordPress installations running on HestiaCP servers. The tool, named wp2shell-Hestia-Scanner, analyzes hosted sites for signs of exploitation, including core file discrepancies, PHP/JS/htaccess modifications, and suspicious images. It also offers per-user email reporting and optional AI-powered evaluation via Claude API. The scanner is designed to help administrators identify potential breaches stemming from these vulnerabilities. The vulnerabilities primarily affect WordPress sites hosted on HestiaCP servers, putting website owners and their visitors at risk of compromise. While the CVE details are not yet fully disclosed, the publication of this scanner suggests these vulnerabilities could allow attackers to gain shell access (wp2shell) on vulnerable systems. The tool's release enables proactive detection, but administrators should monitor for official patches as these CVEs appear to be future-dated (2026), indicating either a typo or potential forward-looking disclosure.
Key Takeaways
- Organizations should review the published PoC and apply vendor patches immediately.
- Public PoC availability lowers the barrier for exploitation by both attackers and security tools.
- Proof of Concept exploit published on GitHub: wp2shell-Hestia-Scanner. Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-6013. A public proof-of-concept exploit has been published for CVE-2026-63030, demonstrating exploitation methodology.