
🌀 CVE‑2026‑64638 – WordPress XSS2Shell Security Suite

⚠️ ETHICAL USE ONLY – AUTHORIZED SECURITY TESTING
This repository provides tools for authorized security professionals, blue teams, and penetration testers only.
Unauthorized access to computer systems is illegal under CFAA (US), Computer Misuse Act (UK), TCK 243/244 (Turkey), and similar laws worldwide.
📖 Vulnerability Overview
CVE‑2026‑64638 is a critical pre‑authentication reflected XSS vulnerability in WordPress core versions 4.7.0 through 7.0.2 that allows an attacker to escalate an XSS attack to full remote code execution (RCE) via the Application Password feature.
How it works
- Parser Differential – PHP's
strip_tags() and WordPress's wp_kses_post() parse HTML tags differently, allowing malicious input to pass sanitization.
- Reflected XSS – an attacker injects a specially crafted payload into the login form (
wp-login.php). Upon failed login, the payload is reflected back and executed in the victim's browser.
- Application Password Abuse – the injected JavaScript automatically generates an Application Password through the WordPress REST API, exfiltrating it to the attacker.
- Plugin Upload (RCE) – using the captured Application Password, the attacker authenticates to the admin panel and uploads a malicious plugin containing a webshell.
- Full System Compromise – the webshell provides system command execution, allowing reverse shells, persistence, lateral movement, and complete server takeover.
Affected Versions
- WordPress 4.7.0 – 7.0.2 – vulnerable
- WordPress 7.0.3 and later – patched
- Security updates have been backported to all maintained branches
Patch
- Upgrade to WordPress 7.0.3 or newer.
- If upgrade is not possible, disable Application Password feature as a temporary workaround.
| Tool | Purpose | Intended User |
|---|
exploit.py | Full exploitation toolkit with reverse shell, persistence, C2, privilege escalation, memory forensics, database dump, SSH key extraction, and mass scanning. | Red teams / authorized pentesters |
safecheck.py | Non‑intrusive vulnerability checker that detects XSS reflection and assesses security posture without executing any malicious payload. Generates detailed reports. | Blue teams / security auditors |
📊 Feature Comparison
| Feature | exploit.py | safecheck.py |
|---|
| Vulnerability detection | ✅ | ✅ |
| WordPress version detection | ✅ | ✅ |
| XSS reflection detection | ✅ | ✅ |
| Application Password capture | ✅ | ❌ |
| Plugin upload (RCE) | ✅ | ❌ |
| Reverse shell | ✅ | ❌ |
| C2 beaconing (HTTP/DNS/Telegram) | ✅ | ❌ |
| Privilege escalation | ✅ | ❌ |
| Memory forensics | ✅ | ❌ |
| Database dump | ✅ | ❌ |
| SSH key extraction | ✅ | ❌ |
| Persistence methods | ✅ | ❌ |
| Security headers audit | ❌ | ✅ |
| Config file exposure check | ❌ | ✅ |
| Directory listing check | ❌ | ✅ |
| phpinfo exposure check | ❌ | ✅ |
| Mass scanning | ✅ | ✅ |
| Proxy support | ✅ | ✅ |
| Tor support | ✅ | ✅ |
| Ngrok tunneling | ✅ | ❌ |
| Interactive shell | ✅ | ❌ |
| Non‑intrusive (safe) mode | ❌ | ✅ |
| JSON / report output | ✅ | ✅ |
🎯 Use Case Summary
| Scenario | Recommended Tool |
|---|
| Blue Team – verifying if your WordPress installation is vulnerable | safecheck.py |
| Security Audit – non‑intrusive vulnerability assessment | safecheck.py |
| Red Team – authorized penetration testing with full exploitation | exploit.py |
| Bug Bounty – responsible disclosure testing | safecheck.py |
| Mass Scanning – checking multiple targets for vulnerability | exploit.py or safecheck.py |
| Incident Response – checking if systems are compromised | safecheck.py |
| Advanced Post‑Exploitation – persistence, C2, forensics | exploit.py |
⚙️ Installation
git clone https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
cd CVE-2026-64638-PoC-Exploit
pip install -r requirements.txt
requirements.txt
requests
urllib3
#ops
pymysql
mysql-connector-python
PySocks
requests[socks]
📋 Parameters
exploit.py Parameters
| Parameter | Description |
|---|
-t, --target | Target WordPress URL (e.g. https://wordpress-site.com) |
-l, --list | File containing list of targets (one per line) for mass scanning |
--lhost | Local IP address for reverse shell callbacks |
--lport | Local port for reverse shell (default: 4444) |
--proxy | HTTP/HTTPS proxy (e.g. http://127.0.0.1:8080) |
--timeout | Request timeout in seconds (default: 10) |
--retry | Number of retries (default: 3) |
--threads | Number of threads for mass scanning (default: 5) |
--exploit | Auto‑exploit vulnerable targets during mass scan |
--ngrok-token | Ngrok authtoken for external tunneling |
--payload-type | XSS payload type: reflected, dom_based, waf_bypass, case_manipulation, double_encoded |
--session-hijack | Enable session hijacking (steal admin cookies) |
--dump-db | Dump WordPress database (requires pymysql) |
--extract-ssh | Extract SSH keys from the target system |
--tor | Route traffic through Tor (socks5h://127.0.0.1:9050) |
--stealth | Enable stealth mode (spoof headers, delay requests) |
--no-cleanup | Skip log cleanup after exploitation |
--ssl-verify | Verify SSL certificates |
--c2-type | C2 type: http, dns, telegram |
--c2-server | C2 server URL or Telegram bot token |
--auto-priv-esc | Auto privilege escalation after shell |
--memory-forensics | Enable memory forensics module |
-v, --verbose | Verbose output |
-q, --quiet | Quiet mode (minimal output) |
safecheck.py Parameters
| Parameter | Description |
|---|
-t, --target | Target WordPress URL (e.g. https://wordpress-site.com) |
-l, --list | File containing list of targets (one per line) for mass scanning |
--timeout | Request timeout in seconds (default: 10) |
--retry | Number of retries (default: 3) |
--threads | Number of threads for mass scanning (default: 5) |
--proxy | HTTP/HTTPS proxy (e.g. http://127.0.0.1:8080) |
--tor | Route traffic through Tor (socks5h://127.0.0.1:9050) |
--ssl-verify | Verify SSL certificates |
--output | Output JSON report file |
-v, --verbose | Verbose output |
-q, --quiet | Quiet mode (minimal output) |
💥 Scenarios