New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

BugShield free tool · CVE-2026-64638

Free WordPress XSS2Shell checker.

Check your WordPress site for the login-page behaviour linked to CVE-2026-64638. The free, non-destructive check requires no plugin or account.

Free XSS2Shell checker · CVE-2026-64638

Enter your website URL and we will check whether it is vulnerable to XSS2Shell.

What is XSS2Shell?

From a failed login to code on the server

XSS2Shell (CVE-2026-64638) is built into WordPress itself. It starts as XSS on the login screen. If an administrator can be socially engineered into the chain, it can end with remote code execution on the server.

Step 1

A failed login that injects HTML

A crafted username on the WordPress login screen can leave markup in the error message that should never have rendered as live page content.

Step 2

Attacker code on your login page

WordPress’s own login scripts then interact with that markup, so malicious JavaScript runs under your domain without needing a password.

Step 3

An admin gets pulled in

If a logged-in administrator hits the trap, the attacker can create an Application Password as that admin and keep API access afterwards.

Step 4

Plugin upload, then code on the server

With that access, a malicious plugin can be uploaded. PHP under wp-content/plugins is reachable even before anyone clicks Activate.

When people say “full remote code execution,” they mean the attacker can run commands as the web server user (often www-data). That is enough to read wp-config.php, dump the database, and plant backdoors. We wrote the longer version in our WordPress XSS2Shell blog post.

What the XSS2Shell checker looks for

A real check, not a guess from a version number alone

When you submit a URL, BugShield runs a non-destructive XSS2Shell check against that site. We are looking for whether the login page still reflects the flaw that starts this chain. We are not uploading plugins, planting shells, or trying to break into the site.

Vulnerable

The site still shows the login flaw. Update WordPress to the security release for your branch straight away.

Not vulnerable

The reflection that starts XSS2Shell was not found. Keep WordPress updated anyway. Security releases keep coming.

Unknown

We could not finish a clear check. Confirm the version under Dashboard > Updates and compare it with the table below.

What the result can and cannot confirm

The XSS2Shell checker tests the public login-page response and uses the detected WordPress version as a fallback. It does not log in, execute the later attack chain, or inspect private files. A clear result helps you decide whether an update is urgent, but it cannot prove that a previously exposed site was never compromised.

Patched versions

XSS2Shell patched WordPress versions

WordPress shipped fixes for maintained branches back to 4.7. Update to at least the version listed for your branch. Newer patch levels on that same branch are fine too.

Branch Minimum patched version
7.0.x 7.0.3
6.9.x 6.9.6
6.8.x 6.8.7
6.7.x 6.7.6
6.6.x 6.6.6
6.5.x 6.5.9
6.4.x 6.4.9
6.3.x 6.3.9
6.2.x 6.2.10
6.1.x 6.1.11

If you are vulnerable

What to do if the XSS2Shell checker flags your site

Updating WordPress closes the login XSS that starts this chain. After you update, check whether anything odd happened while the site was exposed.

  • Update WordPress to the patched release for your branch, or the latest available.
  • Review Application Passwords for each administrator and revoke anything you do not recognise.
  • Check wp-content/plugins for folders you did not install.
  • Rotate admin passwords and review users with the Administrator role. If things look wrong, our malware removal service can dig properly.

Need a human on it?

BugShield developers can help with emergency cleanup, hardening, and ongoing WordPress care: monitoring, backups, and secure credential sharing through the Password Vault.

FAQs

Questions about the XSS2Shell checker

What is XSS2Shell?

XSS2Shell (CVE-2026-64638) is a WordPress vulnerability that starts as XSS on the login screen and can escalate to remote code execution if a logged-in administrator is socially engineered. WordPress shipped fixes for maintained branches. Use our free XSS2Shell checker to test your site.

How does the XSS2Shell checker work?

The XSS2Shell checker sends one non-destructive failed-login probe and reads the public response for the vulnerable reflection behaviour. If that response does not provide a clear answer, it uses the publicly detected WordPress version as a fallback.

Is the XSS2Shell checker free?

Yes. The BugShield XSS2Shell checker is free to use and does not require an account, payment, or plugin installation.

Is the XSS2Shell check safe for my website?

The check is designed to be non-destructive. It does not log in, create users, upload plugins, execute the remote-code chain, or change website content. Only test websites you own or have permission to assess.

Which WordPress versions are patched against XSS2Shell?

WordPress patched XSS2Shell in 7.0.3 and released matching fixes for older maintained branches back to 4.7.34. Update to the latest release available for your branch. The complete minimum-version table is on the XSS2Shell checker page.

What does a Likely vulnerable result mean?

Likely vulnerable means the login page reflected the XSS2Shell probe, or the detected WordPress version falls within a vulnerable range. Update WordPress immediately, then run the checker again.

What does a Not vulnerable result mean?

Not vulnerable means the checker did not find the reflection and did not identify a WordPress version in the known vulnerable ranges. Keep WordPress current because this result is specific to XSS2Shell and is not a complete security audit.

Why might the XSS2Shell checker fail to reach a site?

A firewall, bot challenge, hidden login URL, network timeout, or unavailable website can prevent the check from completing. Confirm the installed version under Dashboard > Updates and compare it with the patched-version table.

Does a vulnerable result mean my WordPress site was hacked?

No. It means the vulnerable behaviour or an affected version was detected. It does not prove exploitation. If the site was exposed, review administrator accounts, Application Passwords, plugins, logs, and unexpected file changes.

Can the XSS2Shell checker find other WordPress vulnerabilities?

No. This checker is focused on XSS2Shell and CVE-2026-64638. Use the WordPress site health scan for a broader review of public software, security, SSL, performance, and SEO signals.

What should I do after updating a vulnerable WordPress site?

Rerun the XSS2Shell checker, revoke unfamiliar Application Passwords, review administrator users, and inspect wp-content/plugins for unknown folders. If anything looks suspicious, request WordPress malware removal.

Keep WordPress updated and watched

Shield plans include monitoring, backups, and developers when something breaks, so the next WordPress security emergency is not a scramble.

Compare plans