CVE-2026-64638, a high-severity WordPress Core vulnerability, starts as a pre-authentication reflected XSS on the login screen and can be chained to PHP code execution when a logged-in administrator is successfully targeted. The issue affects all versions of WordPress, with version 7.0.3 containing the fix and backported through branches eligible for security fixes down to the 4.7 branch. The vulnerability begins as a parsing inconsistency on the login page where an invalid username value is included in an error message returned to the browser, which can allow attacker-controlled HTML elements to survive sanitization and later become active elements in the browser. This results in reflected XSS without the need for an initial WordPress account. The chain of exploitation involves unauthenticated malicious input, reflected XSS on the login page, JavaScript execution in the WordPress origin, abuse of a logged-in administrator session, privileged WordPress actions, and ultimately PHP code execution on the server. A key distinction is that this vulnerability requires successful social engineering and explicit interaction by the target victim to escalate to RCE, targeting an authenticated user with sufficient WordPress privileges.
We recommend you to update WordPress Core to version 7.0.3.[/subscribe_to_unlock_form]
CVE-2026-64638, a high-severity WordPress Core vulnerability, starts as a pre-authentication reflected XSS on the login screen and can be chained to PHP code execution when a logged-in administrator is successfully targeted. The issue affects all versions of WordPress, with version 7.0.3 containing the fix and backported through branches eligible for security fixes down to the 4.7 branch. The vulnerability begins as a parsing inconsistency on the login page where an invalid username value is included in an error message returned to the browser, which can allow attacker-controlled HTML elements to survive sanitization and later become active elements in the browser. This results in reflected XSS without the need for an initial WordPress account. The chain of exploitation involves unauthenticated malicious input, reflected XSS on the login page, JavaScript execution in the WordPress origin, abuse of a logged-in administrator session, privileged WordPress actions, and ultimately PHP code execution on the server. A key distinction is that this vulnerability requires successful social engineering and explicit interaction by the target victim to escalate to RCE, targeting an authenticated user with sufficient WordPress privileges.
We recommend you to update WordPress Core to version 7.0.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]