logo

WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution

ID: 231ec71f-22ca-584c-9523-ef00cd900ccb

STIX ID: report--231ec71f-22ca-584c-9523-ef00cd900ccb

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-08

Date Updated: 2026-08-10

Author: Eswar

...
...

WordPress patched CVE-2026-64638 (XSS2Shell), a high-severity (CVSS 8.9) vulnerability that begins as an unauthenticated XSS on wp-login.php due to a parser disagreement between strip_tags() and the KSES sanitizer. The flaw allows pre-auth script execution by injecting elements that trigger existing user-profile.js behavior and can be escalated to full RCE if a site administrator is later tricked into interacting with attacker-controlled content, enabling actions like minting Application Passwords and uploading plugin web shells. WordPress released an emergency fix in 7.0.3 and backports; site owners should update immediately and check for unexpected application passwords or plugins as potential IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.