Pre-auth Reflected XSS Vulnerability in WordPress
CVE-2026-64638
Key Information:
Badges
What is CVE-2026-64638?
CVE-2026-64638 is a pre-authentication reflected cross-site scripting (XSS) vulnerability affecting WordPress, a widely-used content management system. This vulnerability specifically resides in the login interface of WordPress and can be exploited by attackers to craft malicious third-party sites. If successfully executed, this vulnerability has the potential to escalate to a remote code execution (RCE) threat, contingent upon certain conditions controlled by the attacker. The exploitation of this vulnerability hinges on social engineering tactics to prompt targeted users into interacting with the malicious site. Since WordPress serves as a backbone for millions of websites, any successful exploitation could lead to severe ramifications for affected organizations, including compromised site integrity and user data.
To mitigate the risks associated with this vulnerability, WordPress has released version 7.0.3, which includes fixes for CVE-2026-64638. Furthermore, patches have been backported to older versions dating back to 4.7, ensuring broad coverage for users still on legacy systems.
Potential impact of CVE-2026-64638
-
Website Compromise: Exploitation of this vulnerability could enable attackers to execute scripts in the context of the user's session, potentially leading to unauthorized actions on the site such as data manipulation or defacement, thus undermining the trust users have in the affected organization.
-
Data Breaches: If attackers leverage this vulnerability to escalate to RCE, they could gain unauthorized access to sensitive information stored on the server, resulting in significant data breaches that compromise user privacy and lead to legal repercussions.
-
Reputational Damage: Organizations facing successful exploitation of this vulnerability risk significant reputational harm, as users expect their data to be secure. This can result in lost customer trust and revenue, impacting long-term business viability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
NITDA warns WordPress users over vulnerability that could give attackers website control
Nigeria’s National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites.
2 weeks ago
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution - IT Security News
2026-08-08 11:08 WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the...
3 weeks ago
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server.
3 weeks ago

References
EPSS Score
31% chance of being exploited in the next 30 days.
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved