WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

straight into the rendered login web page, with no account and no prior authentication required.

WordPress XSS2Shell Vulnerability

These injected parts aren’t scripts themselves, however they’re crafted to match selectors that WordPress’s personal user-profile.js file robotically searches for on web page load, a script left over from password-reset performance.

This causes the browser to auto-trigger a click on occasion that cascades into an AJAX request, and thru a way referred to as DOM clobbering, the attacker’s injected factor hijacks the vacation spot URL of that request.

Pointed at WordPress’s REST API with method-override and JSONP parameters, the request comes again wrapped in executable JavaScript, giving the attacker arbitrary script execution contained in the WordPress origin, purely pre-authenticated, pwn.ai said.

By itself, this mirrored XSS is already critical, however WordPress’s advisory and unbiased evaluation affirm that below particular circumstances it will probably escalate to distant code execution.

If a logged-in administrator is lured to a malicious third-party web page and interacts with it, the attacker’s script can piggyback on the admin’s session to mint a WordPress Software Password, publish a web page containing attacker JavaScript utilizing the admin’s unfiltered_html privileges, and at last add a plugin ZIP file containing a PHP net shell, all by way of official, authenticated WordPress API calls the admin by no means explicitly accepted.

WordPress’s official advisory notes that this escalation path requires social engineering and specific sufferer interplay, components outdoors the attacker’s direct management, which is why the CVE carries a CVSS rating of 8.9 quite than a most ranking.

WordPress shipped an emergency fix in version 7.0.3, launched on August 6, 2026, alongside eleven different safety patches. Given the severity, the WordPress safety workforce backported the repair all the way in which to model 4.7, overlaying each department nonetheless receiving safety updates.

There’s at present no proof of lively in-the-wild exploitation or a public proof-of-concept exploit, in line with vulnerability trackers monitoring the CVE. Web site house owners and directors ought to replace to WordPress 7.0.3 or the corresponding backported patch instantly, since most managed hosts apply this robotically however self-hosted websites usually require handbook intervention.

The underlying method builds on a 2022 Identical Origin Methodology Execution (SOME) analysis method revealed by Paulos Yibelo, which was initially used to bypass Content material Safety Coverage protections on WordPress websites and was nominated for High Internet Hacking Strategy of the yr.

 Strengthen Your SOC by Accelerating Menace Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *