WordPress · Wordpress · CVE-2026-64638
**Name of the Vulnerable Software and Affected Versions**
WordPress (affected versions not specified)
**Description**
WordPress is subject to a pre-authentication reflected cross-site scripting (XSS) issue on the login screen. This allows an attacker to execute arbitrary JavaScript in the site origin without requiring authentication. Under specific deployment conditions and with an authenticated Administrator, this flaw can be chained to achieve remote code execution (RCE), which is the ability to execute arbitrary PHP code on the server.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.