WordPress has released a security update: 7.0.3. The big fix targets a high-severity flaw in the core login flow, CVE-2026-64638—nicknamed “XSS2Shell.” The scary part: attackers may not need a valid WordPress account to start. By injecting malicious input that triggers reflected XSS in the login page error handling, the payload can—under specific conditions—“escalate” into server-side PHP execution. Public details point to the WordPress login page: when a non-existent username is submitted, the input is reflected into error messages. Even worse, different HTML filtering stages around the login form handle abnormal markup inconsistently, so dangerous fragments may survive and get parsed as real HTML by the browser. In real-world exploitation, attackers still need to chain the login page’s JavaScript, the site’s REST API, and browser same-origin interactions. If a victim is already logged in as an admin, the attacker can potentially leverage the existing session to obtain the application password key, deploy malicious JS pages, and upload a plugin containing PHP. Imperva observed large-scale automated scanning/locking: 11,000+ sites across 67 countries. #WordPress #CyberSecurity #Vulnerability #XSS #RCE #PatchNow
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论