PT-2026-68882 · WordPress · Wordpress

·

CVE-2026-64638

·

Published

2026-08-06

·

Updated

2026-08-30

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WordPress (affected versions not specified)
Description WordPress is subject to a pre-authentication reflected cross-site scripting (XSS) issue on the login screen. This allows an attacker to execute arbitrary JavaScript in the site origin without requiring authentication. Under specific deployment conditions and with an authenticated Administrator, this flaw can be chained to achieve remote code execution (RCE), which is the ability to execute arbitrary PHP code on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11411
CVE-2026-64638

Affected Products

Wordpress