# manpisetsu/wp2shell > PoC exploit for a WordPress Core vulnerability chain (CVE-2026-63030 and CVE-2026-60137) that gives an unauthenticated attacker RCE via SQL injection and admin account creation. - Magnitude: 4.5 out of 10 — Early signal - Stars: 88 total · +7 stars measured 2026-10-08, 12:31–14:12 UTC, ≈ 18 by evening - Star trust: star growth looks organic - Category: Security · Language: Python · Created: 2026-10-07 · Last push: 2026-10-07 - GitHub: https://github.com/manpisetsu/wp2shell · Page: https://gitnova.dev/en/r/manpisetsu/wp2shell ## Useful for - Check a WordPress site for the vulnerability using check mode - Dump logins and password hashes from wp_users via SQL injection - Get RCE on the server without credentials using shell mode ## Why it’s here - Star-counter measurements on 2026-10-08 (UTC), 12:31–14:12: 81 → 88 stars (+7). This is the change over that interval. - Estimated end-of-day forecast: about +19 stars, using observed gains and the previous day. - The repository is 1 day old and already has 88 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #189. - About 32 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 32 - Issues and pull requests: 0 - Watchers: 6 - Average over the last week: 38 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 4 ## Stars per day, last 5 days (oldest → newest, today is partial) 2026-10-04 … 2026-10-08: 0, 0, 0, 57, 7 ## Spotted in now - Top new repositories this week: #189 ## More in this category 1. **mhtsec/ARTEX** — 7.2 · Early signal · Security · Go · +244 stars measured 2026-10-08, 11:46–14:11 UTC, ≈ 340 by evening AI autonomous penetration testing system with a Go backend and Next.js frontend: agents explore assets and hunt for vulnerabilities, with traffic recording, human-in-the-loop approval, and asset sync from ScopeSentry. Full card: https://gitnova.dev/en/r/mhtsec/ARTEX.md 2. **jiwoochris/artex-ko** — 7.2 · Early signal · Security · Go · +290 stars measured 2026-10-08, 00:02–14:11 UTC, ≈ 440 by evening Korean-localized edition of ARTEX, an autonomous penetration-testing framework driven by multi-agent LLMs (Go backend + Next.js) that plans and executes attack steps on its own. Aimed at security practitioners studying and defending… Full card: https://gitnova.dev/en/r/jiwoochris/artex-ko.md 3. **M-Abozaid/esp32-c3-adblock** — 7.0 · Breakout · Security · C++ · +117 stars measured 2026-10-08, 00:01–14:11 UTC, ≈ 217 by evening A Pi-hole-style DNS ad-blocker running on a cheap ESP32-C3 without PSRAM: domains are stored as 40-bit hashes in flash and binary-searched. UDP DNS sinkhole with a web dashboard. Full card: https://gitnova.dev/en/r/M-Abozaid/esp32-c3-adblock.md 4. **strands-agents/box** — 6.6 · Early signal · Security · Rust · +108 stars measured 2026-10-08, 00:02–14:11 UTC, ≈ 172 by evening An open-source sandbox for AI agents that combines OS isolation with default-deny Dogwood policies, restricting what agents can execute, read, write, and reach on the network. Written in Rust, currently for macOS on Apple silicon. Full card: https://gitnova.dev/en/r/strands-agents/box.md 5. **Stellar-hush/hush** — 5.7 · Early signal · Security · TypeScript · +1 star measured 2026-10-08, 00:09–14:11 UTC, ≈ 22 by evening Open-source beta for private email on Stellar: encrypted messages, sender-controlled inbox policies, optional postage, and verifiable delivery receipts. Stellar handles identity and protocol actions while message content stays off-chain. Full card: https://gitnova.dev/en/r/Stellar-hush/hush.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-08 14:34 UTC, updated every 30 minutes.