logo

XSS2Shell Vulnerability Puts 500 Million WordPress Sites at Risk of RCE

ID: 0af6dcc8-fc7f-5782-a94f-35bd73ee7a93

STIX ID: report--0af6dcc8-fc7f-5782-a94f-35bd73ee7a93

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

Author: Deeba Ahmed

...
...

WordPress released patches for CVE-2026-64638 (“XSS2Shell”), a pre-auth reflected XSS on wp-login.php that can be chained to server-side PHP execution if an authenticated administrator is tricked into interacting with a malicious page; updates (including WordPress 7.0.3 and maintenance releases back to 4.7) should be applied immediately. The flaw was disclosed and demonstrated by pwn.ai, which estimated some 500M+ sites were vulnerable prior to the fixes, but neither pwn.ai nor WordPress reported evidence of active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.