Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4187 articles · 222157 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-64638PATCHED
wordpress · wordpress

CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici

Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Affected Products

VendorProductVersions
wordpresswordpress—

References

  • https://hackerone.com/reports/3877102
  • https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-64638.yaml(exploit, nuclei)

Related News (11 articles)

Tier D
Heise Security43d ago
WordPress-Lücke: Login-Seite öffnet Tür zur Serverübernahme
→ No new info (linked only)
Tier D
The Hacker News45d ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
→ No new info (linked only)
Tier B
CCCS Canada45d ago
WordPress security advisory (AV26-792)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity45d ago
XSS2Shell: Pre-Auth XSS in WordPress Login (CVE-2026-64638) Walkthrough
→ No new info (linked only)
Tier B
CERT-FR45d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier E
Hacker News47d ago
WordPress CVE-2026-64638 Pre-Auth XSS to RCE
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-64638 | WordPress up to 7.0.2 Login Screen cross site scripting
→ No new info (linked only)
Tier E
Reddit r/cybersecurity48d ago
New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?
→ No new info (linked only)
Tier D
The Hacker News48d ago
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
→ No new info (linked only)
Tier B
BSI Advisories48d ago
[NEU] [hoch] WordPress: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR48d ago
Multiples vulnérabilités dans WordPress (07 août 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
0
CWECWE-79
PublishedAug 7, 2026
Trending Score1
Source articles11
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-87902EXPKEV
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
Trending: 135
CRITICALCVE-2026-63030EXPKEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending: 4
MEDIUMCVE-2026-60137EXPKEV
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Trending: 3
HIGHCVE-2026-65640
CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Trending: 1
CRITICALCVE-2026-6382EXP
Multiple elFinder Plugins - Authenticated OS Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 7, 2026
Discovered by ZDM
Aug 7, 2026
Exploit Available
Aug 7, 2026
Patch Available
Aug 7, 2026