The vulnerability tracked as CVE-2026-64638 allows an attacker to get a shell on a WordPress server if an authenticated administrator clicks on a crafted link.
Stormhield Network Security (SNS) appliance protects you from that attack, thanks to a dedicated IPS Signature. To work efficiently, the traffic needs to be decrypted.
| ID | Name |
| http:client:data.203 | Exploitation of the XSS2Shell vulnerability in WordPress (CVE-2026-64638) |
