Act
active
WordPress Pre-Auth XSS (CVE-2026-64638) Chains to PHP RCE
- Engineer — Act: Public PoC exists on GitHub for a flaw affecting every WordPress version; update WordPress core to the patched release immediately, as the chain to server-side PHP execution is demonstrated even though it requires an admin to visit an attacker page.
- SOC/IR — Plan: With a public PoC but EPSS of 0.01 and no KEV listing, active exploitation is not yet confirmed; build or tune a detection for anomalous reflected XSS patterns hitting the WordPress login endpoint and alert on unexpected admin-session activity following external link clicks.
- Leader — Skip
- Signals: CVE-2026-64638 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.