megachangelog
Security2026-08-07

WAF Updates: WordPress XSS (CVE-2026-64638) and Command Injection Rule Disabling

Updated WordPress XSS rule metadata in the Managed and Free Rulesets to identify CVE-2026-64638, a pre-authentication reflected cross-site scripting vulnerability on WordPress login screens. Also disabled the Command Injection - Obfuscation rule as its detection logic has been deprecated.

This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.

Key Findings

  • CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...9c6dff1cN/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Free Ruleset...9ab5ed95N/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed Ruleset...761e7a4cN/ACommand Injection - ObfuscationBlockDisabledDetection logic has been deprecated
wafsecuritywordpressxsscve-2026-64638command-injection

Source: original entry ↗