CVE-2026-64638-PoC-XSS2Shell-
Author
Boreas37
Published
2026-08-07
Stars
13
Forks
3
Repository
Description
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
CVE-CVE-2026-64638 Details
Severity
UNKNOWN
CVSS Score
0.0
CWE
CWE-79
Description
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and...
Related PoCs for CVE-2026-64638
XSS2Shell-CVE-2026-64638...
4
Linuxhackingid-official
CVE-2026-64638-PoC-Exploit...
1
tc4dy
CVE-2026-64638...
1
4minx
poc-CVE-2026-64638-...
0
mohwahyudi
CVE-2026-64638-POC...
0
imbas007
xss2shell...
0
0xlipon
CVE-2026-64638-XSS-to-Shell-PoC...
0
eh-amish