WordPress是美国基金会开源的一款一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。 WordPress 7.0.3之前版本存在跨站脚本漏洞,该漏洞源于登录屏幕存在反射型跨站脚本漏洞,在特定条件下可能升级为远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Pre-authentication reflected XSS in WordPress wp-login.php (CVE-2026-64638). The flaw exploits a parser differential between PHP strip_tags() and WordPress KSES. Tags with whitespace after < (e.g. "< area") survive strip_tags() but are normalized to valid HTML by KSES, leading to attacker-controlled DOM elements that trigger automatic JavaScript execution via user-profile.js. No user interaction required. Affects all WordPress versions < 7.0.3. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-64638.yaml | POC Details |
No comments yet