CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-64638: WordPress Pre-Auth Reflected XSS (XSS2Shell)

August 7, 2026

CVE-2026-64638 is a pre-authentication reflected XSS vulnerability in WordPress, rated 8.9 on the CVSS scale, that can be exploited to achieve PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.