https://reddit.com/r/cybersecurity/comments/1vkg8n0/xss2shell_preauth_xss_in_wordpress_login/: XSS2Shell: Pre-Auth XSS in WordPress Login (CVE-2026-64638) Walkthrough
Published Aug 10, 2026
·Updated
Affected Software
1 affected component
WordPress WordPress
Frequently Asked Questions
1
What is the severity of CVE-2026-64638?
CVE-2026-64638 is classified as a high severity vulnerability due to its potential for pre-authentication cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-64638?
To fix CVE-2026-64638, update your WordPress installation to the latest version where the vulnerability is patched.
3
What are the risks associated with CVE-2026-64638?
The risks of CVE-2026-64638 include unauthorized access and the potential for attackers to execute malicious scripts in users' browsers.
4
Who is affected by CVE-2026-64638?
All versions of WordPress prior to the patch release for CVE-2026-64638 are affected by this vulnerability.
5
What type of attack does CVE-2026-64638 facilitate?
CVE-2026-64638 facilitates reflected XSS attacks that can be exploited even before user authentication.