WordPress Releases Security Updates to Address "XSS2Shell" Vulnerability Chain
Successful exploitation of CVE-2026-64638 could potentially lead to PHP code execution
Summary
Successful exploitation of CVE-2026-64638 could potentially lead to PHP code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Technical details released for CVE-2026-64638
Security researchers have released technical details the CVE-2026-64638 exploit chain dubbed "XSS2Shell" containing a proof-of-concept exploit.
The NHS England National CSOC assesses exploitation as likely.
Introduction
WordPress have released a security update for WordPress Core to address an attack chain dubbed "XSS2Shell".
- CVE-2026-64638 - Reflected cross-site scripting (XSS) vulnerability with a CVSSv4.0 score of 8.9. A remote unauthenticated attacker could exploit this vulnerability to execute JavaScript code in the context of the browser.
Security researchers have stated that it is possible for CVE-2026-64638 to escalate to a remote code execution (RCE) vulnerability with conditions outside of the attackers control.
Remediation advice
Affected organisations are encouraged to review WordPress Core 7.0.3 release and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 7 August 2026 3:58 pm