What is CVE-2026-64638?
The XSS2Shell WordPress Core vulnerability (CVE-2026-64638) exploits an XSS bug on the login page to escalate into a more serious risk. This attack chain affects exposed WordPress sites, requiring immediate patching.
Azərbaycanca: XSS2Shell adlı WordPress nüvə zəifliyi (CVE-2026-64638) giriş səhifəsindəki XSS qüsurundan istifadə edərək daha ciddi təhlükələrə səbəb olur. Bu zəncirvari hücum açıq WordPress saytlarını təsir edir, dərhal təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Where does the XSS2Shell vulnerability (CVE-2026-64638) reside?
CVE-2026-64638 exploits an XSS bug on the WordPress login page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.