DIRAS TAKE
Urgent: public exploit code is available, so defenders should prioritize mitigations that reduce exposure of WordPress login endpoints and block malicious input at the edge.
What is CVE-2026-64638?
An attacker can craft web content that triggers a reflected cross-site scripting flaw against WordPress login pages, allowing code to run in the context of a victim's browser and, with user interaction and social engineering, potentially enabling further impacts; this is tracked as CVE-2026-64638. All reported WordPress versions are affected. Exploitation requires a victim to visit or interact with attacker-controlled content and does not require prior authentication to the target site. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of WordPress WordPress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| WordPress | all versions |
Is CVE-2026-64638 being exploited?
Public exploit code is available.
How to fix CVE-2026-64638
- Restrict access to the WordPress login page (rate-limit, IP allowlist, or move behind VPN or admin-only network).
- Deploy or tune a web application firewall to block suspicious URL parameters and known XSS payloads targeting login endpoints.
- Harden user-facing defenses: enable browser security features (HTTP-only and secure cookies, Content Security Policy) where possible and require multi-factor authentication for accounts.
- Monitor logs for unusual requests to the login page and for signs of successful script injection; follow vendor guidance and apply updates when a vendor patch is released.
Frequently asked questions
Is CVE-2026-64638 being actively exploited?
Public exploit code is available for CVE-2026-64638.
Which WordPress versions are affected by CVE-2026-64638?
According to the available information, all WordPress versions are affected by CVE-2026-64638.
Is there a patch for CVE-2026-64638?
There is no patch reported as available for CVE-2026-64638.
Does CVE-2026-64638 require authentication?
No; CVE-2026-64638 is a pre-auth reflected XSS on the WordPress login screen, but it does require user interaction and social engineering of the victim.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64638
- cve.org/CVERecord?id=CVE-2026-64638
- hackerone.com/reports/3877102
- wordpress.org/news/2026/08/wordpress-7-0-3-release
- All WordPress CVEs on CVE Radar
- CVEs published in September 2026