Description
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
Weaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- XSS-уязвимость в WordPress приводит к выполнению PHP-кодаru-ru·Хакер (xakep.ru)· PoC WordPress rce
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Adminsen·The Hacker News· Exploited WordPress supply-chain
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- 10th August – Threat Intelligence Reporten-us·Check Point Research· Roundup North Carolina Ports Systems UNC6671
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPen·The Hacker News· Patch WordPress
- WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixeden·Patchstack· Patch WordPress patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-64638 and every CVE in our database. Create a free account — no credit card required.
Create Free Account