How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Imperva Customers Protected Against XSS2Shell (CVE-2026-64638) in WordPress Core

calendar_today August 10, 2026 person Muly Levy domain imperva

TL;DR: CVE-2026-64638, dubbed XSS2Shell, is a high-severity WordPress Core vulnerability that begins as a pre-authentication reflected XSS on the login screen and can be chained to PHP code execution when a logged-in administrator is successfully targeted. WordPress fixed the issue in 7.0.3 and backported the fix through maintained branches. Imperva Cloud WAF and On-Prem WAF […] The post Imperva Customers Protected Against XSS2Shell (CVE-2026-64638) in WordPress Core appeared first on Blog .

open_in_new Read original post