Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
xss2shell — 🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit | Kitploit
Tools/GitHubGitHub/0xlipon/xss2shell
Defensive ToolsReconnaissanceVulnerability ScannersWeb Vulnerability ScannersPayload GenerationVulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration Testing
GitHub0xlipon/xss2shell

xss2shell

3261 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

View RepositoryWebsite
Share

CVE-2026-64638 CVSS 8.9 pwn.ai Python 3.8+

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

Behavior-first mass scanner and evidence-grade PoC generator for the WordPress pre-auth XSS-to-RCE chain affecting 500M+ websites.
Detection only. No weaponization. Built for bug bounty programs and blue teams.

Official Checker: https://pwn.ai/xss2shell-checker.html

What is this? • Quick Start • Shodan Dorks • Usage • Decision Matrix • Detection • FAQ


🔎 Shodan Dorks

Hunt for potentially vulnerable WordPress instances across the internet before scanning:

Core WordPress Discovery

http.component:"wordpress" -http.title:"Just a moment"

Finds WordPress sites while excluding Cloudflare "I'm Under Attack" mode / bot-protection pages that will block or challenge automated requests.

Narrow to Login Pages

http.component:"wordpress" http.title:"Log In"

Returns only WordPress login pages — the exact attack surface for CVE-2026-64638.

Version-Specific Hunting

http.component:"wordpress" "wp-content" "?ver=7.0" -"?ver=7.0.3"

Flags WordPress 7.0.x instances without the 7.0.3 patch by asset version fingerprinting.

Widen the Surface

http.component:"wordpress" http.html:"wp-login.php"

Catches sites where wp-login.php is reachable but may not be the current page — broader coverage.

Cloudflare Exclusions (Combined)

http.component:"wordpress" -http.title:"Just a moment" -http.title:"Attention Required" -org:"Cloudflare"

Aggressive filter that strips out most Cloudflare-fronted targets. Use when scanning at scale with --active — Cloudflare will rate-limit or block the probe request.

Tip: Export Shodan results with shodan download and pipe the hostnames directly into xss2shell_mass.py -i.


🚨 What Is CVE-2026-64638?

On August 7, 2026, pwn.ai disclosed CVE-2026-64638 (XSS2Shell) — a critical pre-authentication cross-site scripting vulnerability in WordPress Core that chains all the way to remote code execution on the server. [citation:pwn.ai blog]

The bug exploits a parser disagreement between PHP's strip_tags() and WordPress's wp_kses_post():

  • strip_tags() uses < immediately followed by a letter to identify HTML tags. < area id=...> (with a space) is treated as text — it survives.
  • wp_kses_post() (KSES) recognizes < area as a valid <area> element — and <area> is allowlisted in KSES. [citation:pwn.ai blog]

One failed login with a specially crafted username < area id=ajaxurl href=/?rest_route=/&_method=GET&_jsonp=alert>... bypasses both sanitizers, gets rendered as live DOM on the login page, hijacks WordPress's own user-profile.js script via DOM clobbering, and fires alert() in the WordPress origin — zero clicks, zero authentication, zero cookies required. [citation:pwn.ai blog]

Escalated to a logged-in administrator? The same primitive steals Application Passwords via Same Origin Method Execution (SOME), uploads a malicious plugin, and executes PHP as www-data. [citation:pwn.ai blog] [citation:hadrian.io blog]

Affected: WordPress 6.4 through 7.0.2 — patched in 7.0.3 with backports to 4.7+.
Impact: ~500 million websites at time of disclosure. [citation:pwn.ai blog]

📰 Key Resources

ResourceLink
Original Disclosure (pwn.ai)pwn.ai/blog/xss2shell
Hadrian Technical Analysishadrian.io/blog/wordpress-xss2shell
WordPress Advisory (GHSA)GHSA-52p2-r8wf-jcrf
SOME Attack Research (2022)pwn.ai/blog/bypass-csp-using-wordpress
WordPress 7.0.3 Releasewordpress.org/news/2026/08/wordpress-7-0-3-release

⚡ What This Toolkit Does

This is a detection-only toolkit. It does not weaponize the vulnerability — it gives security researchers, bug bounty hunters, and blue teams everything needed to:

  1. Mass-scan hundreds of WordPress hosts in minutes with behavioral-first accuracy
  2. Generate evidence-grade PoC pages to prove the XSS fires (alert() only)
  3. Classify findings with precise confidence levels — no false positives from version-matching

🔑 Why Behavior-First?

"A version string says what patch level the code should be.
Only the login-page sanitizer behavior says whether the bug fires."

Managed hosts silently backport security patches without bumping version strings. Login-hardening plugins replace the error message entirely, killing the reflection channel even on insecure versions. Version-only scanners produce false positives and false negatives. This scanner sends a single benign probe and classifies the actual sanitizer behavior.


🚀 Quick Start

Installation

git clone https://github.com/jakestone/xss2shell.git
cd xss2shell
pip install -r requirements.txt

5-Minute Scan

# Passive — no probes sent to target, version + endpoint fingerprinting only
python3 xss2shell_mass.py -i domains.txt -o results

# Active — sends ONE benign failed-login per host (authorized assets only!)
python3 xss2shell_mass.py -i domains.txt -o results --active --workers 80

Generate Evidence PoCs

# Single target
python3 make_poc.py --target https://blog.example.com

# Batch from scanner output
python3 make_poc.py --from-results results.csv -o pocs/

Open the generated .poc.html in your browser while recording video → if alert() fires, you've captured pre-auth XSS evidence.


📖 Usage

Mass Scanner (xss2shell_mass.py)

usage: xss2shell_mass.py [-h] -i INPUT [-o OUTPUT]
                         [--active] [--workers WORKERS]
                         [--timeout TIMEOUT] [--quiet]
FlagDescription
-i, --inputFile with one host per line (bare domain or full URL)
-o, --outputBase path for output files (generates .csv + .json)
--activeEnable behavioral probe — one failed login per host
--workersThread pool size (default: 50, max ~200 for good connections)
--timeoutHTTP timeout in seconds (default: 10)
--quietOnly print confirmed_vulnerable, vulnerable, and likely_vulnerable

Passive Scan Evidence (no active probe, always collected)

  1. Homepage → WordPress fingerprint (meta generator, asset ?ver= params, wp-content references)
  2. Login page → Reachability, stock login form detection, user-profile.js gadget enqueued, core asset versions
  3. REST JSONP smoke test → Harmless GET on /?rest_route=/&_method=GET&_jsonp=<random> — is the JSONP pathway open?
  4. Feed/Readme fallback → Version extraction if homepage fingerprint is missing

Active Probe (one POST, --active flag)

Download Tool