辻 伸弘 (nobuhiro tsuji)[verified]@ntsujiDisclosure
The post discloses a new WordPress RCE chain, XSS2Shell, exploiting CVE-2026-64638 reflected XSS on the login screen, detailing the attack steps but offers no PoC, exploit code, or patch information.
Sekurak[verified]@SekurakDisclosure
The post announces CVE-2026‑64638, a pre‑authentication XSS in WordPress that can evolve into RCE, and urges users to update their installations, with a link to a detailed chain explanation.
Professor Larry Densel[verified]@luckyhacker43Disclosure
The post announces the new CVE-2026-64638 (a WordPress login XSS leading to RCE), provides a detection template, and gives basic technical details, but does not mention exploitation, patches, or false‑positive status.
NITDA Nigeria[verified]@NITDANigeriaPatch
An advisory highlights a critical pre-authentication XSS vulnerability in WordPress (CVE-2026-64638) and advises users to update to WordPress Core 7.0.3 to mitigate the risk.
ThreatWire[verified]@ThreatWire_Patch
WordPress has issued a patch for CVE‑2026‑64638, a pre‑authentication XSS‑to‑RCE vulnerability affecting all versions, with the fix available in WordPress 7.0.3. The flaw allows attackers to use a crafted username to execute arbitrary PHP code.
Rıdvan Yağlı[verified]@ridvanyagliDisclosure
WordPress Core CVE-2026-64638 (XSS2Shell) is disclosed as a pre‑authentication reflected XSS leading to RCE via admin interaction; patches issued in WP 7.0.3 and earlier releases, with a write‑up available.
Aikido Community Japan[verified]@AikidoCommJPPatch
The Twitter post discusses the newly discovered CVE-2026-64638, an XSS-to-shell vulnerability in WordPress Core found via wp2shell; it urges users to upgrade immediately and notes reports of active exploitation.
Dipak Gajjar[verified]@dipakcgajjarPatch
The CVE‑2026‑64638 login‑page bug that lets attackers run code via a link is now fixed in the latest WordPress release; users are urged to update.