https://reddit.com/r/cybersecurity/comments/1vi1ydb/new_wordpress_preauth_xss_cve202664638_could_lead/: New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?
Published Aug 7, 2026
·Updated
Affected Software
1 affected component
WordPress WordPress<7.0.3
Frequently Asked Questions
1
What is the severity of CVE-2026-64638?
CVE-2026-64638 is classified as a high-severity vulnerability due to its potential impact on WordPress instances.
2
How do I fix CVE-2026-64638?
To fix CVE-2026-64638, update your WordPress installation to version 7.0.3 or to the latest version that includes the security patch.
3
What are the potential consequences of CVE-2026-64638?
If exploited, CVE-2026-64638 could lead to remote code execution through pre-authentication reflected XSS on the login page.
4
Which versions of WordPress are affected by CVE-2026-64638?
CVE-2026-64638 affects multiple versions of WordPress, including those prior to the 7.0.3 update.
5
Who discovered CVE-2026-64638?
CVE-2026-64638 was discovered by the cybersecurity team at pwn.ai.