1.
The research team disclosed XSS2Shell, a pre-auth reflected XSS in the WordPress login screen that can be escalated to remote code execution when the required user interaction and deployment conditions are met. The issue affects maintained WordPress Core versions; WordPress 7.0.3 fixes it and the fix was backported to maintained branches back to 4.7. The linked research includes technical details and a public PoC.
Why it matters: WordPress powers a large share of internet-facing sites. The pre-auth login-screen XSS can execute JavaScript in the site origin after victim interaction and, under the documented conditions, be chained into impact on administrator sessions and the server. Upgrade to WordPress 7.0.3 or the corresponding patched maintenance branch, then review login activity, administrator sessions, and unexpected plugins or file changes. The current CVE record assigns CVSS 4.0 8.9 (High) and requires active user interaction; no active-exploitation signal is currently recorded.
Skip to content