BugShield free tool · CVE-2026-64638
XSS2Shell WordPress checker
Enter your site URL and we will check whether it is vulnerable to XSS2Shell. Free, no install, and built around a non-destructive check rather than an attack.
Free XSS2Shell checker · CVE-2026-64638
What is XSS2Shell?
From a failed login to code on the server
XSS2Shell (CVE-2026-64638) is built into WordPress itself. It starts as XSS on the login screen. If an administrator can be socially engineered into the chain, it can end with remote code execution on the server.
Step 1
A failed login that injects HTML
A crafted username on the WordPress login screen can leave markup in the error message that should never have rendered as live page content.
Step 2
Attacker code on your login page
WordPress’s own login scripts then interact with that markup, so malicious JavaScript runs under your domain without needing a password.
Step 3
An admin gets pulled in
If a logged-in administrator hits the trap, the attacker can create an Application Password as that admin and keep API access afterwards.
Step 4
Plugin upload, then code on the server
With that access, a malicious plugin can be uploaded. PHP under wp-content/plugins is reachable even before anyone clicks Activate.
When people say “full remote code execution,” they mean the attacker can run commands as the web server user (often www-data). That is enough to read wp-config.php, dump the database, and plant backdoors. We wrote the longer version in our WordPress XSS2Shell blog post.
How the XSS2Shell checker works
A real check, not a guess from a version number alone
When you submit a URL, BugShield runs a non-destructive XSS2Shell check against that site. We are looking for whether the login page still reflects the flaw that starts this chain. We are not uploading plugins, planting shells, or trying to break into the site.
Vulnerable
The site still shows the login flaw. Update WordPress to the security release for your branch straight away.
Not vulnerable
The reflection that starts XSS2Shell was not found. Keep WordPress updated anyway. Security releases keep coming.
Unknown
We could not finish a clear check. Confirm the version under Dashboard > Updates and compare it with the table below.
Patched versions
Minimum safe WordPress releases
WordPress shipped fixes for maintained branches back to 4.7. Update to at least the version listed for your branch. Newer patch levels on that same branch are fine too.
| Branch | Minimum patched version |
|---|---|
| 7.0.x | 7.0.3 |
| 6.9.x | 6.9.6 |
| 6.8.x | 6.8.7 |
| 6.7.x | 6.7.6 |
| 6.6.x | 6.6.6 |
| 6.5.x | 6.5.9 |
| 6.4.x | 6.4.9 |
| 6.3.x | 6.3.9 |
| 6.2.x | 6.2.10 |
| 6.1.x | 6.1.11 |
| 6.0.x | 6.0.13 |
| 5.9.x | 5.9.14 |
| 5.8.x | 5.8.14 |
| 5.7.x | 5.7.16 |
| 5.6.x | 5.6.18 |
| 5.5.x | 5.5.19 |
| 5.4.x | 5.4.20 |
| 5.3.x | 5.3.22 |
| 5.2.x | 5.2.25 |
| 5.1.x | 5.1.23 |
| 5.0.x | 5.0.26 |
| 4.9.x | 4.9.30 |
| 4.8.x | 4.8.29 |
| 4.7.x | 4.7.34 |
If you are vulnerable
Update now, then take a quick look round
Updating WordPress closes the login XSS that starts this chain. After you update, check whether anything odd happened while the site was exposed.
- Update WordPress to the patched release for your branch, or the latest available.
- Review Application Passwords for each administrator and revoke anything you do not recognise.
- Check
wp-content/pluginsfor folders you did not install. - Rotate admin passwords and review users with the Administrator role. If things look wrong, our malware removal service can dig properly.
Need a human on it?
BugShield developers can help with emergency cleanup, hardening, and ongoing WordPress care: monitoring, backups, and secure credential sharing through the Password Vault.
FAQs
XSS2Shell questions
What is XSS2Shell?
XSS2Shell (CVE-2026-64638) is a WordPress vulnerability that starts as XSS on the login screen and can escalate to remote code execution if a logged-in administrator is socially engineered. WordPress shipped fixes for maintained branches. Use our free XSS2Shell checker to test your site.
Which WordPress versions are patched?
Update to at least 7.0.3 on the 7.0 branch, or the matching security release on older maintained branches (for example 6.9.6, 6.8.7, 6.7.6, back through 4.7.34). Newer patch levels on the same branch are fine. The full table is on the XSS2Shell checker page.
What does this checker actually do?
It runs a non-destructive check against the URL you submit. We look for whether the login page still reflects the XSS2Shell flaw. We do not upload plugins, create admin accounts, or try to take over the site.
What does Unknown mean?
Unknown means we could not finish a clear check for that URL. Confirm your WordPress version under Dashboard > Updates and compare it with the patched release table on the tool page.
If I was vulnerable, what should I do besides updating?
Update WordPress first. Then revoke unexpected Application Passwords, review administrator users, and inspect wp-content/plugins for anything you did not install. If you need help, see WordPress malware removal or request a one-off fix.
Keep WordPress updated and watched
Shield plans include monitoring, backups, and developers when something breaks, so the next WordPress security emergency is not a scramble.
Compare plans