Vulnerability Report

CVE-2026-64638

Title: Pre-auth Reflected XSS in WordPress Login Screen

XSS

Proof Of Concept

PoC Available for CVE-2026-64638

CWE Category CWE-79
Published Date Aug 07, 2026
Modified Date Aug 07, 2026
Exploit Status Available
Score 8.9 CVSS v4.0
Exploit Probability (EPSS)
0.77%

Vulnerability Summary

CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

CVSS v4.0
Source Entity [email protected]
Severity HIGH
8.9
Attack Vector
NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
ACTIVE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
N/A
RAW VECTOR CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-64638 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/5yu4n/CVE-2026-64638
View Code
GitHub https://github.com/Boreas37/CVE-2026-64638-PoC
View Code
GitHub https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
View Code
GitHub https://github.com/0xBlackash/CVE-2026-64638
View Code
GitHub https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
View Code
GitHub https://github.com/wordsec/XSS2Shell
View Code
GitHub https://github.com/HackSpeak/CVE-2026-64638
View Code
GitHub https://github.com/Linuxhackingid-official/XSS2Shell-CVE-2026-64638
View Code
GitHub https://github.com/Boreas37/CVE-2026-64638-PoC-XSS2Shell-
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity HIGH
Privileges N/A
Interaction ACTIVE
CVSS Vector String CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Stack

No specific products linked.