logo

CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution

ID: 27dbe6ae-1118-5505-8d31-68a70c54f283

STIX ID: report--27dbe6ae-1118-5505-8d31-68a70c54f283

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-08-07

Date Updated: 2026-08-07

Author: Do Son

...
...

WordPress 7.0.3 has been released as a security update fixing about a dozen flaws, with the most serious being CVE-2026-64638 — a pre-auth reflected XSS (CVSS ~8.9) that can be escalated to remote code execution via social engineering; site owners should update immediately as fixes are being backported to older branches and no public exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.