Security2026-08-07
WAF Updates: WordPress XSS (CVE-2026-64638) and Command Injection Rule Disabling
Updated WordPress XSS rule metadata in the Managed and Free Rulesets to identify CVE-2026-64638, a pre-authentication reflected cross-site scripting vulnerability on WordPress login screens. Also disabled the Command Injection - Obfuscation rule as its detection logic has been deprecated.
This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.
Key Findings
- CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.
Impact
The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | ...9c6dff1c | N/A | Wordpress - XSS - CVE:CVE-2026-64638 | Block | N/A | Rule metadata description refined. Detection unchanged. |
| Cloudflare Free Ruleset | ...9ab5ed95 | N/A | Wordpress - XSS - CVE:CVE-2026-64638 | Block | N/A | Rule metadata description refined. Detection unchanged. |
| Cloudflare Managed Ruleset | ...761e7a4c | N/A | Command Injection - Obfuscation | Block | Disabled | Detection logic has been deprecated |
wafsecuritywordpressxsscve-2026-64638command-injection
Source: original entry ↗