Cross-site scripting in WordPress - CVE-2026-64638
Published: August 7, 2026
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the login screen. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information and potentially compromise the affected website.
Affected software
Fedora
wordpress
How to mitigate CVE-2026-64638
wordpress - addressed in versions 6.9.6-1.el9, 6.9.6-1.el10_2, 6.9.6-1.fc43, 6.9.6-1.fc44, 7.0.3-1.el10_3