CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

WordPress Pre-Auth XSS Vulnerability CVE-2026-64638

August 7, 2026

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting vulnerability in WordPress's login screen. It allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser, which can be chained to achieve PHP code execution on the server when an administrator interacts with an attacker-controlled page. The flaw was patched in WordPress 7.0.3 and backported to earlier versions.