PoC Archive PoC Archive

tag

Application-Password

WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181) EPSS 15%
CVE-2026-8181 web Patched
CVE-2026-8181webCRITICAL 9.8Patched2026-07-05