
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
Behavior-first mass scanner and evidence-grade PoC generator for the WordPress
pre-auth XSS-to-RCE chain affecting 500M+ websites.
Detection only. No weaponization. Built for bug bounty programs and blue teams.
What is this? • Quick Start • Shodan Dorks • Usage • Decision Matrix • Detection • FAQ
Hunt for potentially vulnerable WordPress instances across the internet before scanning:
http.component:"wordpress" -http.title:"Just a moment"
Finds WordPress sites while excluding Cloudflare "I'm Under Attack" mode / bot-protection pages that will block or challenge automated requests.
http.component:"wordpress" http.title:"Log In"
Returns only WordPress login pages — the exact attack surface for CVE-2026-64638.
http.component:"wordpress" "wp-content" "?ver=7.0" -"?ver=7.0.3"
Flags WordPress 7.0.x instances without the 7.0.3 patch by asset version fingerprinting.
http.component:"wordpress" http.html:"wp-login.php"
Catches sites where wp-login.php is reachable but may not be the current page — broader coverage.
http.component:"wordpress" -http.title:"Just a moment" -http.title:"Attention Required" -org:"Cloudflare"
Aggressive filter that strips out most Cloudflare-fronted targets. Use when scanning at scale with --active — Cloudflare will rate-limit or block the probe request.
Tip: Export Shodan results with
shodan downloadand pipe the hostnames directly intoxss2shell_mass.py -i.
On August 7, 2026, pwn.ai disclosed CVE-2026-64638 (XSS2Shell) — a critical pre-authentication cross-site scripting vulnerability in WordPress Core that chains all the way to remote code execution on the server. [citation:pwn.ai blog]
The bug exploits a parser disagreement between PHP's strip_tags() and WordPress's wp_kses_post():
strip_tags() uses < immediately followed by a letter to identify HTML tags. < area id=...> (with a space) is treated as text — it survives.wp_kses_post() (KSES) recognizes < area as a valid <area> element — and <area> is allowlisted in KSES. [citation:pwn.ai blog]One failed login with a specially crafted username < area id=ajaxurl href=/?rest_route=/&_method=GET&_jsonp=alert>... bypasses both sanitizers, gets rendered as live DOM on the login page, hijacks WordPress's own user-profile.js script via DOM clobbering, and fires alert() in the WordPress origin — zero clicks, zero authentication, zero cookies required. [citation:pwn.ai blog]
Escalated to a logged-in administrator? The same primitive steals Application Passwords via Same Origin Method Execution (SOME), uploads a malicious plugin, and executes PHP as www-data. [citation:pwn.ai blog] [citation:hadrian.io blog]
Affected: WordPress 6.4 through 7.0.2 — patched in 7.0.3 with backports to 4.7+.
Impact: ~500 million websites at time of disclosure. [citation:pwn.ai blog]
| Resource | Link |
|---|---|
| Original Disclosure (pwn.ai) | pwn.ai/blog/xss2shell |
| Hadrian Technical Analysis | hadrian.io/blog/wordpress-xss2shell |
| WordPress Advisory (GHSA) | GHSA-52p2-r8wf-jcrf |
| SOME Attack Research (2022) | pwn.ai/blog/bypass-csp-using-wordpress |
| WordPress 7.0.3 Release | wordpress.org/news/2026/08/wordpress-7-0-3-release |
This is a detection-only toolkit. It does not weaponize the vulnerability — it gives security researchers, bug bounty hunters, and blue teams everything needed to:
"A version string says what patch level the code should be.
Only the login-page sanitizer behavior says whether the bug fires."
Managed hosts silently backport security patches without bumping version strings. Login-hardening plugins replace the error message entirely, killing the reflection channel even on insecure versions. Version-only scanners produce false positives and false negatives. This scanner sends a single benign probe and classifies the actual sanitizer behavior.
git clone https://github.com/jakestone/xss2shell.git
cd xss2shell
pip install -r requirements.txt
# Passive — no probes sent to target, version + endpoint fingerprinting only
python3 xss2shell_mass.py -i domains.txt -o results
# Active — sends ONE benign failed-login per host (authorized assets only!)
python3 xss2shell_mass.py -i domains.txt -o results --active --workers 80
# Single target
python3 make_poc.py --target https://blog.example.com
# Batch from scanner output
python3 make_poc.py --from-results results.csv -o pocs/
Open the generated .poc.html in your browser while recording video → if alert() fires, you've captured pre-auth XSS evidence.
xss2shell_mass.py)usage: xss2shell_mass.py [-h] -i INPUT [-o OUTPUT]
[--active] [--workers WORKERS]
[--timeout TIMEOUT] [--quiet]
| Flag | Description |
|---|---|
-i, --input | File with one host per line (bare domain or full URL) |
-o, --output | Base path for output files (generates .csv + .json) |
--active | Enable behavioral probe — one failed login per host |
--workers | Thread pool size (default: 50, max ~200 for good connections) |
--timeout | HTTP timeout in seconds (default: 10) |
--quiet | Only print confirmed_vulnerable, vulnerable, and likely_vulnerable |
?ver= params, wp-content references)user-profile.js gadget enqueued, core asset versions/?rest_route=/&_method=GET&_jsonp=<random> — is the JSONP pathway open?--active flag)