CVE-2026-64638 is a pre-authentication reflected XSS vulnerability in WordPress, rated 8.9 on the CVSS scale, that can be exploited to achieve PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.