Exploit for XSS2Shell-CVE-2026-64638

Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.

Published 30 Aug 2026Updated 30 Aug 20263 sources
CVSS 8.9 PoC CANDIDATE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.