logo

XSS2Shell (CVE-2026-64638): Patch WordPress Now

ID: 9b01c84f-0968-534e-a444-30aa707a1dea

STIX ID: report--9b01c84f-0968-534e-a444-30aa707a1dea

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-08-07

Date Updated: 2026-08-10

Author: ameer

...
...

**XSS2Shell (CVE-2026-64638)** is a pre-auth reflected XSS on the WordPress login page that can be chained—when a logged-in administrator interacts with attacker-controlled content and site conditions permit—to potential PHP code execution; the flaw affects WordPress 4.7.0 through 7.0.2 and is fixed in 7.0.3 (with backports), so administrators should patch immediately, review admin and plugin activity, restrict Application Passwords, and monitor the provided detection signals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.