PT-2026-68882 · WordPress · Wordpress
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
WordPress (affected versions not specified)
Description
WordPress is subject to a pre-authentication reflected cross-site scripting (XSS) issue on the login screen. This allows an attacker to execute arbitrary JavaScript in the site origin without requiring authentication. Under specific deployment conditions and with an authenticated Administrator, this flaw can be chained to achieve remote code execution (RCE), which is the ability to execute arbitrary PHP code on the server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress