XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)

Security researchers at pwn.ai disclosed a critical pre-authentication vulnerability in WordPress Core (CVE-2026-64638) that allowed attackers to execute cross-site scripting (XSS) on the login page, leading to remote code execution (RCE) on the server. The exploit abused differences in how WordPress sanitizes HTML, enabling injection of malicious DOM elements that triggered admin-only REST API calls to approve application passwords, publish attacker-controlled scripts, and upload PHP plugins without user interaction. WordPress patched the flaw in version 7.0.3 and backported fixes to all maintained versions; site owners are strongly urged to update immediately.

https://pwn.ai/blog/xss2shell

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top