Skip to content

#188 · XSS2Shell detection is live (CVE-2026-64638)

Availability: General Availability

XSS2Shell is a pre-authentication reflected XSS in WordPress Core, tracked as CVE-2026-64638 with a CVSS 4.0 score of 8.9. A crafted username reaching the failed-login error page runs attacker JavaScript in the site's origin, with no authentication and no further interaction on that page. Against an administrator who is already logged in, the chain escalates to PHP code execution, though that step needs social engineering and a deliberate click. The fix shipped in WordPress 7.0.3 on August 6, backported through the 4.7 branch.

Escape now detects it across DAST and AI Pentesting. Escape now detects it across DAST and AI Pentesting. DAST confirms the injection by sending a single crafted failed login and matching the clobbered DOM elements in the error response, so the result is behavioural evidence rather than a version guess, and it needs no credentials. AI Pentesting walks the full chain and returns proof of exploitation.

Recommended action: connect to your Escape account to verify whether you've been affected, then patch to the security release for your branch. The login screen is internet facing by design, so exposure is broad.

We proactively reach out to our current customers who might have been affected by this issue.

See your exposure in one view

  • Open All Issues.
  • Search for "XSS2Shell".
  • Save as a new view.

You get a live view of every affected asset, with the exposed and unauthenticated counts broken out for triage.

Questions?

Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.