home.social

#xss2shell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xss2shell, aggregated by home.social.

fetched live
  1. 📢 🤖 ⚠️ PwnAi discovered a high-severity WordPress vulnerability called #XSS2Shell, which it estimates affected over 500 million websites. The flaw could turn a failed login into a path for executing malicious code by convincing a logged-in administrator to visit a malicious website.

    Listen/Read: hackread.com/xss2shell-vulnera

    #CyberSecurity #WordPress #Security #Vulnerability

  2. 📢 🤖 ⚠️ PwnAi discovered a high-severity WordPress vulnerability called #XSS2Shell, which it estimates affected over 500 million websites. The flaw could turn a failed login into a path for executing malicious code by convincing a logged-in administrator to visit a malicious website.

    Listen/Read: hackread.com/xss2shell-vulnera

    #CyberSecurity #WordPress #Security #Vulnerability

  3. Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

    Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

    Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

    XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

    ⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
    Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

    Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

    🩹 Corrigé dans WordPress 7.0.3.
    👇
    wordpress.org/news/2026/08/wor

    En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

    "XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
    👇
    pwn.ai/blog/xss2shell

    #WordPress #XSS2Shell #CyberVeille

  4. Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.

    Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.

    Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :

    XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚

    ⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
    Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.

    Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.

    🩹 Corrigé dans WordPress 7.0.3.
    👇
    wordpress.org/news/2026/08/wor

    En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.

    "XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
    👇
    pwn.ai/blog/xss2shell

    #WordPress #XSS2Shell #CyberVeille

  5. Różnica w parsowaniu HTML może doprowadzić do RCE w WordPressie

    WordPress to ta część świata oprogramowania open source, o której na sekuraku piszemy na tyle regularnie, że tym razem już darujemy Wam fragment o tym, jak ważny jest to projekt dla całego internetu. Powodem dzisiejszego wpisu jest łańcuch drobnych błędów zaczynający się od XSS, a po spełnieniu określonych warunków kończący...

    #WBiegu #Rce #Wordpress #XSS #Xss2shell

    sekurak.pl/roznica-w-parsowani

  6. Różnica w parsowaniu HTML może doprowadzić do RCE w WordPressie

    WordPress to ta część świata oprogramowania open source, o której na sekuraku piszemy na tyle regularnie, że tym razem już darujemy Wam fragment o tym, jak ważny jest to projekt dla całego internetu. Powodem dzisiejszego wpisu jest łańcuch drobnych błędów zaczynający się od XSS, a po spełnieniu określonych warunków kończący...

    #WBiegu #Rce #Wordpress #XSS #Xss2shell

    sekurak.pl/roznica-w-parsowani

  7. Another vulnchain discovered at WP Core.

    By visiting a malicious web that has a XSS payload, an attacker can do RCE to a victim Wordpress site.

    While this is not nasty as wp2shell, you should still update your WP Core.

    Technical writeup:
    pwn.ai/blog/xss2shell

    #cybersecurity #infosec #wordpress #vulnerability #vulnerabilityresearch #xss2shell

  8. #Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
    👇
    thehackernews.com/2026/08/new-

  9. #Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
    👇
    thehackernews.com/2026/08/new-