CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution
ID: 27dbe6ae-1118-5505-8d31-68a70c54f283
STIX ID: report--27dbe6ae-1118-5505-8d31-68a70c54f283
Feed Name: securityonline.info
Threat Score
WordPress 7.0.3 has been released as a security update fixing about a dozen flaws, with the most serious being CVE-2026-64638 — a pre-auth reflected XSS (CVSS ~8.9) that can be escalated to remote code execution via social engineering; site owners should update immediately as fixes are being backported to older branches and no public exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
