System running
Last check: 2026-08-10 03:59:48 | Auto-updates every hour
74 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-2026-64638-PoC-XSS2Shell-

CVE-2026-64638 RCE Python #poc #github #cve-2026-64638 #rce
Author
Boreas37
Published
2026-08-07
Stars
13
Forks
3
Description

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

CVE-CVE-2026-64638 Details
Severity
UNKNOWN
CVSS Score
0.0
CWE
CWE-79
Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and...

Related PoCs for CVE-2026-64638
XSS2Shell-CVE-2026-64638...
4 Linuxhackingid-official
CVE-2026-64638-PoC-Exploit...
1 tc4dy
CVE-2026-64638...
1 4minx
poc-CVE-2026-64638-...
0 mohwahyudi
CVE-2026-64638-POC...
0 imbas007
xss2shell...
0 0xlipon
CVE-2026-64638-XSS-to-Shell-PoC...
0 eh-amish
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources