• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

New WordPress Pre-Auth XSS Might Result in PHP Code Execution

Admin by Admin
August 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


WordPress has mounted a pre-authentication mirrored cross-site scripting (XSS) flaw in its login display screen that impacts each model of the content material administration system. pwn.ai demonstrated how the flaw could be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled web page.

Tracked as CVE-2026-64638 (CVSS rating: 8.9), the high-severity vulnerability requires no attacker privileges. In response to pwn.ai, which found the flaw and shared technical particulars with The Hacker Information, the login-page XSS requires no authentication. As soon as a crafted username reaches the failed-login error web page, the ensuing JavaScript executes within the customer’s browser with no additional interplay required on that web page.

The code-execution path requires a sufferer already logged in as an Administrator and express interplay with an attacker-controlled web page. In pwn.ai’s demonstration, that interplay is one peculiar click on.

The researchers instructed The Hacker Information that the assault works in opposition to default WordPress installations and doesn’t require uncommon internet hosting or deployment settings. The researchers mentioned they’ve a number of paths from the XSS to code execution, together with variants that set up a plugin or add an arbitrary ZIP.

WordPress’s personal advisory takes a extra cautious view of exploitability, noting that escalation to RCE includes circumstances outdoors the attacker’s management and requires profitable social engineering plus express sufferer interplay.

The problem was patched on August 6 in WordPress 7.0.3, with fixes backported by the 4.7 department. WordPress recommends updating instantly, and websites that help computerized background updates ought to obtain the safety launch mechanically. Variations older than 4.7 stay affected however fall outdoors the venture’s present backport vary.

The researchers, who name the assault chain XSS2Shell, mentioned its autonomous system found and reproduced the vulnerability chain after being given Paulos Yibelo‘s 2022 Identical Origin Methodology Execution (SOME) analysis as a place to begin.

The corporate mentioned the work took almost 4 days utilizing open-source fashions and a multi-agent workflow. It mentioned the chain was reproduced on July 26 and reported to WordPress the next day.

The flaw begins in the best way WordPress handles the username from a failed login. In response to the researchers, the worth passes by sanitize_user() and wp_strip_all_tags(), which depends on PHP’s strip_tags(). A tag-like string containing whitespace after the opening < can survive that parser as textual content. Later, WordPress passes the worth by wp_kses_post(), whose separate parser interprets the identical enter as permitted HTML. The result’s attacker-controlled stay DOM components on the failed-login web page.

These components then work together with WordPress’s personal user-profile.js, a profile-management script that can also be loaded on the login web page as a result of the web page handles password resets.

Some profile components the script expects are absent there: two lacking inputs each resolve to undefined, permitting an equality examine to move, whereas the in any other case undefined ajaxurl variable could be clobbered with an injected DOM component. That steers WordPress’s personal JavaScript towards an attacker-selected same-origin REST request.

The researchers use WordPress’s REST JSONP help to show that request into JavaScript executing within the web site’s origin. For deployments the place nameless REST requests return HTTP 401, the _envelope=1 parameter can wrap the denial in an outer HTTP 200 response, permitting jQuery to proceed processing the response as script.

The researchers additionally discovered of their testing {that a} nonce-based Content material Safety Coverage utilizing strict-dynamic didn’t block the demonstrated path.

The trail from XSS to PHP execution builds on Yibelo’s earlier SOME approach, which makes use of a permitted JSONP property chain to invoke a technique in one other browser window.

One path demonstrated by pwn.ai makes use of the WordPress-origin XSS to invoke the native Utility Password approval management inside a logged-in Administrator’s session. WordPress then creates an API credential and redirects it to an attacker-selected HTTPS success_url.

Utility Passwords are revocable credentials supposed for API entry, so this path doesn’t have to steal the administrator’s main password. The researchers used the credential for authenticated REST entry to publish a WordPress web page containing same-origin JavaScript. When the retained administrator session opened that web page, its script obtained WordPress’s plugin-upload nonce and uploaded an attacker-supplied ZIP. PHP might then be requested instantly from the extracted plugin. The plugin didn’t have to be activated.

The manufacturing proof provided to The Hacker Information stops on the XSS. The researchers individually reproduced the cookie-less login-page XSS in opposition to two WordPress 7.0.2 deployments in contemporary Chrome profiles with no WordPress cookies or credentials.

They didn’t try Utility Password creation, file add, persistence, or PHP execution on these methods. The entire PHP-execution chain was demonstrated individually on a clear native WordPress 7.0.2 set up.

The researchers mentioned identified WordPress hardening measures shouldn’t be handled as an entire mitigation for the underlying XSS and that making use of the safety replace is required.

A profitable PHP execution would expose WordPress database credentials in wp-config.php, permit persistent administrator creation and content material adjustments, expose recordsdata and secrets and techniques readable by the PHP employee, and allow operating-system instructions with that employee’s privileges.

WordPress credited the crew at pwn.ai with discovering and responsibly disclosing the vulnerability. As of August 7, the venture’s advisory doesn’t report in-the-wild exploitation.

Tags: CodeExecutionLeadPHPPreAuthWordPressXSS
Admin

Admin

Next Post
Indie Xbox Collection X RPGs with Higher Exploration Than Skyrim

Indie Xbox Collection X RPGs with Higher Exploration Than Skyrim

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Native search engine optimization Service Packages in Miami

Native search engine optimization Service Packages in Miami

May 31, 2026
10 Finest Candidate Relationship Administration Software program for 2026

10 Finest Candidate Relationship Administration Software program for 2026

April 3, 2026

Trending.

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

May 31, 2026
100 Most Costly Key phrases for Google Advertisements in 2026

100 Most Costly Key phrases for Google Advertisements in 2026

January 13, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Parental Lock Code Puzzle Defined

Parental Lock Code Puzzle Defined

July 27, 2025
Random Forest Algorithm in Machine Studying With Instance

Random Forest Algorithm in Machine Studying With Instance

May 4, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Indie Xbox Collection X RPGs with Higher Exploration Than Skyrim

Indie Xbox Collection X RPGs with Higher Exploration Than Skyrim

August 7, 2026
New WordPress Pre-Auth XSS Might Result in PHP Code Execution

New WordPress Pre-Auth XSS Might Result in PHP Code Execution

August 7, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved