Skip to main content

WordPress Releases Security Updates to Address "XSS2Shell" Vulnerability Chain

Successful exploitation of CVE-2026-64638 could potentially lead to PHP code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-64638 could potentially lead to PHP code execution


Affected platforms

The following platforms are known to be affected:

Threat details

Technical details released for CVE-2026-64638

Security researchers have released technical details the CVE-2026-64638 exploit chain dubbed "XSS2Shell" containing a proof-of-concept exploit.

The NHS England National CSOC assesses exploitation as likely.


Introduction

WordPress have released a security update for WordPress Core to address an attack chain dubbed "XSS2Shell".

  • CVE-2026-64638 - Reflected cross-site scripting (XSS) vulnerability with a CVSSv4.0 score of 8.9. A remote unauthenticated attacker could exploit this vulnerability to execute JavaScript code in the context of the browser.

Security researchers have stated that it is possible for CVE-2026-64638 to escalate to a remote code execution (RCE) vulnerability with conditions outside of the attackers control.


Remediation advice

Affected organisations are encouraged to review WordPress Core 7.0.3 release and apply the relevant update as soon as possible.



Last edited: 7 August 2026 3:58 pm