Overview
WordPress has patched a pre‑authentication reflected cross‑site scripting (XSS) flaw in its login screen that affects every version of the CMS. Tracked as CVE‑2026‑64638 (CVSS 8.9), the vulnerability requires no attacker privileges and can be chained into PHP code execution when a logged‑in administrator interacts with an attacker‑controlled page.
How the Attack Works
- Pre‑auth XSS: A crafted username triggers JavaScript execution on the failed‑login error page.
- Administrator interaction: Exploit escalates when an admin clicks on a malicious page.
- REST JSONP abuse: Attackers steer WordPress’s own JavaScript toward same‑origin REST requests.
- Application Password hijack: Creates API credentials, enabling plugin upload and PHP execution.
- Technical Details
- Vulnerability arises from how WordPress sanitizes failed login usernames:
sanitize_user()andwp_strip_all_tags()rely on PHP’sstrip_tags().- Tag‑like strings with whitespace survive parsing.
- Later,
wp_kses_post()interprets the same input as permitted HTML, creating attacker‑controlled DOM elements.
- These elements interact with user‑profile.js, loaded on the login page for password resets. Missing inputs resolve to
undefined, allowing equality checks to pass and enabling attackers to overrideajaxurl. - REST JSONP support allows attackers to wrap HTTP 401 responses in HTTP 200, tricking jQuery into executing injected scripts.
Impact
If chained to PHP execution, attackers could:
- Expose WordPress database credentials in
wp-config.php. - Create persistent administrator accounts.
- Upload malicious plugins or files.
- Execute operating system commands with PHP worker privileges.
Defensive Guidance
- Update immediately: Fixed in WordPress 7.0.3, with backports through the 4.7 branch. Versions older than 4.7 remain vulnerable.
- Enable automatic updates: Ensure sites receive security releases promptly.
- Audit administrator activity: Look for suspicious plugin uploads or REST requests.
- Review CSP policies: Strict‑dynamic nonce policies may not block this chain.
- Educate admins: Train users to avoid interacting with untrusted links or pages.
Expert in the Cloud Insight
This vulnerability, dubbed XSS2Shell, shows how even a login‑page XSS can escalate into full remote code execution when combined with social engineering. For defenders, the lesson is clear: patch immediately, treat login pages as high‑risk surfaces, and recognize that XSS is rarely “just a browser bug” — it can become a server‑side compromise.
Leave a Reply