Pre-auth Reflected XSS Vulnerability in WordPress
CVE-2026-64638

8.9HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
7 August 2026

Badges

👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-64638?

CVE-2026-64638 is a pre-authentication reflected cross-site scripting (XSS) vulnerability affecting WordPress, a widely-used content management system. This vulnerability specifically resides in the login interface of WordPress and can be exploited by attackers to craft malicious third-party sites. If successfully executed, this vulnerability has the potential to escalate to a remote code execution (RCE) threat, contingent upon certain conditions controlled by the attacker. The exploitation of this vulnerability hinges on social engineering tactics to prompt targeted users into interacting with the malicious site. Since WordPress serves as a backbone for millions of websites, any successful exploitation could lead to severe ramifications for affected organizations, including compromised site integrity and user data.

To mitigate the risks associated with this vulnerability, WordPress has released version 7.0.3, which includes fixes for CVE-2026-64638. Furthermore, patches have been backported to older versions dating back to 4.7, ensuring broad coverage for users still on legacy systems.

Potential impact of CVE-2026-64638

  1. Website Compromise: Exploitation of this vulnerability could enable attackers to execute scripts in the context of the user's session, potentially leading to unauthorized actions on the site such as data manipulation or defacement, thus undermining the trust users have in the affected organization.

  2. Data Breaches: If attackers leverage this vulnerability to escalate to RCE, they could gain unauthorized access to sensitive information stored on the server, resulting in significant data breaches that compromise user privacy and lead to legal repercussions.

  3. Reputational Damage: Organizations facing successful exploitation of this vulnerability risk significant reputational harm, as users expect their data to be secure. This can result in lost customer trust and revenue, impacting long-term business viability.

Affected Version(s)

WordPress 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.

7 hours ago

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pwn.ai
.