Critical WordPress XSS2Shell Flaw Enables Admin Takeover and RCE

Critical WordPress XSS2Shell Flaw Enables Admin Takeover and RCE

First seen 11 Aug 2026, 08:07 UTC ScworldScmagazine 100% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability chain named XSS2Shell has been identified in WordPress, allowing attackers to gain administrator access and execute arbitrary code on compromised sites. The flaw exploits how WordPress handles usernames during login, bypassing initial HTML sanitization. By using a specially crafted username, attackers can inject malicious elements that trigger actions in an admin's session. This leads to the generation of application passwords, enabling unauthorized access to the REST API with elevated privileges. WordPress has issued patches for versions 4.7 and later, including 7.0.3, and urges users to update immediately to mitigate the risk. The vulnerability affects all sites running the specified versions of WordPress. Security Affairs reported the details of this vulnerability chain.

Key Points: • XSS2Shell allows attackers to take over WordPress admin accounts and execute code. • The vulnerability exploits username handling on the login page, bypassing sanitization. • WordPress has released patches for all affected versions; immediate updates are recommended.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
XSS2Shell vulnerability disclosed
Researchers at Pwn revealed a critical vulnerability in WordPress affecting admin accounts and allowing remote code execution.
Scworld
2026-08-11
WordPress patches released
WordPress issued patches for versions 4.7 and later, including version 7.0.3, urging users to update immediately.
Scmagazine

Community

Browse all →

Tracked Entities in This Story