#xss2shell — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xss2shell, aggregated by home.social.
-
📢 🤖 ⚠️ PwnAi discovered a high-severity WordPress vulnerability called #XSS2Shell, which it estimates affected over 500 million websites. The flaw could turn a failed login into a path for executing malicious code by convincing a logged-in administrator to visit a malicious website.
Listen/Read: https://hackread.com/xss2shell-vulnerability-wordpress-sites-rce-risk/
-
📢 🤖 ⚠️ PwnAi discovered a high-severity WordPress vulnerability called #XSS2Shell, which it estimates affected over 500 million websites. The flaw could turn a failed login into a path for executing malicious code by convincing a logged-in administrator to visit a malicious website.
Listen/Read: https://hackread.com/xss2shell-vulnerability-wordpress-sites-rce-risk/
-
Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur
wp-login.php.Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell -
Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur
wp-login.php.Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell -
Różnica w parsowaniu HTML może doprowadzić do RCE w WordPressie
WordPress to ta część świata oprogramowania open source, o której na sekuraku piszemy na tyle regularnie, że tym razem już darujemy Wam fragment o tym, jak ważny jest to projekt dla całego internetu. Powodem dzisiejszego wpisu jest łańcuch drobnych błędów zaczynający się od XSS, a po spełnieniu określonych warunków kończący...
#WBiegu #Rce #Wordpress #XSS #Xss2shell
https://sekurak.pl/roznica-w-parsowaniu-html-moze-doprowadzic-do-rce-w-wordpressie/
-
Różnica w parsowaniu HTML może doprowadzić do RCE w WordPressie
WordPress to ta część świata oprogramowania open source, o której na sekuraku piszemy na tyle regularnie, że tym razem już darujemy Wam fragment o tym, jak ważny jest to projekt dla całego internetu. Powodem dzisiejszego wpisu jest łańcuch drobnych błędów zaczynający się od XSS, a po spełnieniu określonych warunków kończący...
#WBiegu #Rce #Wordpress #XSS #Xss2shell
https://sekurak.pl/roznica-w-parsowaniu-html-moze-doprowadzic-do-rce-w-wordpressie/
-
Another vulnchain discovered at WP Core.
By visiting a malicious web that has a XSS payload, an attacker can do RCE to a victim Wordpress site.
While this is not nasty as wp2shell, you should still update your WP Core.
Technical writeup:
https://pwn.ai/blog/xss2shell#cybersecurity #infosec #wordpress #vulnerability #vulnerabilityresearch #xss2shell
-
#Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
👇
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html -
#Wordpress: A Critical pre-auth #XSS to RCE vulnerability chain (CVE-2026-64638) dubbed #XSS2Shell is affecting all versions of WordPress Core. This vulnerability was discovered by AI (@pwn_ai). Patch to v7.0.3 ASAP - older versions backported:
👇
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html