High severityNVD Advisory· Published Aug 7, 2026· Updated Sep 3, 2026
CVE-2026-64638
CVE-2026-64638
Description
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: all versions prior to 7.0.3 (backported to 4.7)
Patches
Vulnerability mechanics
References
2News mentions
8- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsThe Hacker News · Aug 11, 2026
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsThe Hacker News · Aug 10, 2026
- 10th August – Threat Intelligence ReportCheck Point Research · Aug 10, 2026
- WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code ExecutionCyber Security News · Aug 7, 2026
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPThe Hacker News · Aug 7, 2026
- WordPress 7.0.3 Released: 12 Vulnerabilities Found and FixedPatchstack Blog · Aug 6, 2026
- WordPress 7.0.3 releaseWordPress Core Security · Aug 6, 2026