• PoC PUBLIC

CVE-2026-64638: pre-auth reflected xss in WordPress WordPress

An attacker can craft web content that triggers a reflected cross-site scripting flaw against WordPress login pages, allowing code to run in the context of a victim's browser and, with user interaction and social engineering, potentially enabling further impacts; this is tracked as CVE-2026-64638. All reported WordPress versions are affected. Exploitation requires a victim to visit or interact with attacker-controlled content and does not require prior authentication to the target site.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
8.9HIGH
EPSS
0.00894
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available, so defenders should prioritize mitigations that reduce exposure of WordPress login endpoints and block malicious input at the edge.

What is CVE-2026-64638?

An attacker can craft web content that triggers a reflected cross-site scripting flaw against WordPress login pages, allowing code to run in the context of a victim's browser and, with user interaction and social engineering, potentially enabling further impacts; this is tracked as CVE-2026-64638. All reported WordPress versions are affected. Exploitation requires a victim to visit or interact with attacker-controlled content and does not require prior authentication to the target site. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WordPress WordPress are affected?

BRANCHAFFECTEDFIXED
WordPressall versions

Is CVE-2026-64638 being exploited?

Public exploit code is available.

How to fix CVE-2026-64638

  1. Restrict access to the WordPress login page (rate-limit, IP allowlist, or move behind VPN or admin-only network).
  2. Deploy or tune a web application firewall to block suspicious URL parameters and known XSS payloads targeting login endpoints.
  3. Harden user-facing defenses: enable browser security features (HTTP-only and secure cookies, Content Security Policy) where possible and require multi-factor authentication for accounts.
  4. Monitor logs for unusual requests to the login page and for signs of successful script injection; follow vendor guidance and apply updates when a vendor patch is released.

Frequently asked questions

Is CVE-2026-64638 being actively exploited?

Public exploit code is available for CVE-2026-64638.

Which WordPress versions are affected by CVE-2026-64638?

According to the available information, all WordPress versions are affected by CVE-2026-64638.

Is there a patch for CVE-2026-64638?

There is no patch reported as available for CVE-2026-64638.

Does CVE-2026-64638 require authentication?

No; CVE-2026-64638 is a pre-auth reflected XSS on the WordPress login screen, but it does require user interaction and social engineering of the victim.

References