WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
PoC: XSS2Shell-CVE-2026-64638
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
PoC: Cve-2026-64638
Educational use only!
PoC: CVE-2026-64638
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing
PoC: CVE-2026-64638
CVE-2026-64638 (XSS2shell) POC.
PoC: CVE-2026-64638
CVE-2026-64638
[POC] CVE-2026-64638 — XSS2Shell
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
[POC] CVE-2026-64638 — POC-WP-XSS2Shell-CVE-2026-64638
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
[POC] CVE-2026-64638 — CVE-2026-64638-PoC
XSS2Shell (CVE-2026-64638) PoC — WordPress pre-auth XSS to RCE chain
PoC: xss2shell-check
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
PoC: CVEX2SHEL
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.
PoC: xss2shell
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
PoC: XSS2Shell
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.
PoC: XSS2Shell-CVE-2026-64638
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
PoC: CVE-2026-64638-PoC-Exploit
🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd
PoC: CVE-2026-64638-POC
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
PoC: CVE-2026-64638-WordPress-Core-XSS2Shell
Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.
PoC: CVE-2026-64638
CVE-2026-64638
PoC: CVE-2026-64638
CVE-2026-64638 - Draft or TODO
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free