AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-64638

HIGH · CVSS 8.9 EPSS 0.89%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

WordPress is susceptible to a pre-auth reflected XSS vulnerability on the login screen, which can potentially be escalated to a remote code execution (RCE) vulnerability through social engineering tactics targeting users. This issue affects all versions of WordPress, necessitating immediate attention from website administrators and users to upgrade to version 7.0.3 or apply the backported fix for older versions. Organizations relying on WordPress for their web presence should prioritize addressing this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-64638
Severity
HIGH
CVSS
8.9
EPSS
0.89%
WordPress

Original NVD Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).