XSS2Shell (CVE-2026-64638): Patch WordPress Now
ID: 9b01c84f-0968-534e-a444-30aa707a1dea
STIX ID: report--9b01c84f-0968-534e-a444-30aa707a1dea
Feed Name: SOCRadar Blog
Threat Score
**XSS2Shell (CVE-2026-64638)** is a pre-auth reflected XSS on the WordPress login page that can be chained—when a logged-in administrator interacts with attacker-controlled content and site conditions permit—to potential PHP code execution; the flaw affects WordPress 4.7.0 through 7.0.2 and is fixed in 7.0.3 (with backports), so administrators should patch immediately, review admin and plugin activity, restrict Application Passwords, and monitor the provided detection signals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
