WordPress Login Screen - Pre-Auth Reflected XSS
WordPress login screen (wp-login.php) is vulnerable to pre-authentication reflected cross-site scripting (XSS). A specially crafted URL causes arbitrary JavaScript execution in a victim's browser context. Under conditions outside the attacker's control, this may be escalated to remote code execution via social engineering. All WordPress versions prior to 7.0.3 are affected; the fix has been backported to all branches back to 4.7. The advisory does not disclose the exact vulnerable parameter; this template probes common wp-login.php query parameters for unescaped HTML reflection as a best-effort black-box detection method.
Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.
What this check actually does
- Fingerprints the host — server, technologies, certificate and response headers.
- Runs the WordPress Login Screen - Pre-Auth Reflected XSS detection against it.
- Runs a short pass for common misconfigurations, exposed files and TLS problems.
- Cross-references the detected versions against published CVEs.
Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.