System running
Last check: 2026-08-10 03:59:48 | Auto-updates every hour
74 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-2026-64638

CVE-2026-64638 XSS HTML #poc #github #cve-2026-64638 #xss
Author
4minx
Published
2026-08-08
Stars
1
Forks
0
Description

CVE-2026-64638 (XSS2shell) POC.

CVE-CVE-2026-64638 Details
Severity
UNKNOWN
CVSS Score
0.0
CWE
CWE-79
Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and...

Related PoCs for CVE-2026-64638
CVE-2026-64638-PoC-XSS2Shell-...
13 Boreas37
XSS2Shell-CVE-2026-64638...
4 Linuxhackingid-official
CVE-2026-64638-PoC-Exploit...
1 tc4dy
poc-CVE-2026-64638-...
0 mohwahyudi
CVE-2026-64638-POC...
0 imbas007
xss2shell...
0 0xlipon
CVE-2026-64638-XSS-to-Shell-PoC...
0 eh-amish
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources