CSP
CSP stops XSS2Shell: inside the WordPress pre-auth XSS to RCE chain (CVE-2026-64638)
No injected <script> tag. Nothing loaded from an attacker-controlled origin. A PHP shell at the end of it. A CSP kills this chain on the login page, and can tell you when someone tries. That's exactly what we're for. WordPress shipped an emergency