Cross-site scripting in WordPress - CVE-2026-64638
Published: August 7, 2026 / Updated: August 21, 2026
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the login screen. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information and potentially compromise the affected website.
Affected software
Debian Linux
Fedora
wordpress (Debian package)
wordpress
How to mitigate CVE-2026-64638
wordpress (Debian package) - update to 6.8.7+dfsg1-0+deb13u1
wordpress - addressed in versions 6.9.6-1.el9, 6.9.6-1.el10_2, 6.9.6-1.fc43, 6.9.6-1.fc44, 6.9.7-1.el9, 6.9.7-1.el10_2, 6.9.7-1.fc43, 6.9.7-1.fc44, 7.0.3-1.el10_3, 7.0.4-1.el10_3
Links to Public Exploits and PoC-codes
- Exploit #12968 - CVE-2026-64638-POC (CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC) (August 21, 2026)
- Exploit #12928 - CVE-2026-64638-PoC-XSS2Shell- (XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template) (August 14, 2026)
- Exploit #12923 - XSS2Shell (Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)) (August 14, 2026)
- Exploit #12914 - XSS2Shell (XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress (August 14, 2026)
- Exploit #12897 - CVE-2026-64638-PoC-Exploit (?️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. ? Safe Check & Exploit, 2 mode. Advanced Blue&Red Team B (August 14, 2026)
- Exploit #12892 - XSS2Shell (XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress (August 14, 2026)
External References
Related Security Bulletins
- Multiple vulnerabilities in WordPress
- Fedora EPEL 10.3 update for wordpress
- Fedora 44 update for wordpress
- Fedora EPEL 9 update for wordpress
- Fedora EPEL 10.2 update for wordpress
- Fedora 43 update for wordpress
- Debian update for wordpress
- Fedora EPEL 10.3 update for wordpress
- Fedora EPEL 10.2 update for wordpress
- Fedora 44 update for wordpress
- Fedora EPEL 9 update for wordpress
- Fedora 43 update for wordpress