XSS2Shell
PythonDockerWordPressExploit
An educational proof of concept of the XSS2Shell chain (CVE-2026-64638): a pre-auth reflected XSS in wp-login.php affecting all WordPress Core versions before 7.0.3 (CVSS 8.9), shipped as an emergency security release in August 2026. It demonstrates going from an XSS to remote code execution. Includes a reproducible Docker lab, a Python attacker server, a technical analysis of the chain and mitigation. For educational and research purposes only.