logo

XSS2Shell (CVE-2026-64638): WordPress Login Page Pre-Auth XSS to RCE Chain Explained

ID: 5001b7eb-13ec-5aaf-bf1f-dbc33cdd2bf6

STIX ID: report--5001b7eb-13ec-5aaf-bf1f-dbc33cdd2bf6

Feed Name: Brandefense Blog

Threat Score
72/100

Date Published: 2026-08-07

Date Updated: 2026-08-10

Author: Tutku Özel

...
...

The report titled "XSS2Shell (CVE-2026-64638): WordPress Login Page Pre-Auth XSS to RCE Chain Explained" describes a vulnerability in WordPress where a pre-auth XSS on the login page can be chained to achieve remote code execution (RCE), indicating a significant security issue affecting WordPress instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.