Skip to main content

CVE detail

CVE-2026-64638

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

CVSS 8.9 · HighBuzz score 45.01 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 45.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 5.5
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
20.0
6 sources across 5 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
5.5
1 repos · best confidence 0.80
Best PoC traction
5
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
6
within the 30d window
Peak daily
4
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • 10th August – Threat Intelligence ReportCheck Point Research

    gle Gemini CLI and Anthropic Claude Code that could expose automation environments to code execution and API key theft. CVE-2026-12537, rated CVSS 10.0, affected Gemini CLI workflows, while CVE-2026-54316 affected Claude Code. Both vendors released patched versions. Researchers have detailed AI-enabled identity fraud kits that automate know-your-custom

    vendorresearch.checkpoint.comAug 10, 2026, 1:53 PM
  • ck Switzerland’s Federal IT Agency INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog 31,000 Records Compromised in Breach of Liechtenstein Companies and Foundation

    newssecurityaffairs.comAug 9, 2026, 11:49 AM
  • Linked URL: https://pwn.ai/blog/xss2shell | Posted by thepill | 1 points | 0 comments

    communitynews.ycombinator.comAug 7, 2026, 7:30 PM
  • No excerpt available.

    Release Noteswordpress.orgAug 7, 2026, 6:17 PM
  • https://hackerone.com/reports/3877102hackerone.com

    No excerpt available.

    Exploithackerone.comAug 7, 2026, 6:17 PM
  • PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity

    newsthehackernews.comAug 7, 2026, 12:56 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.80 · max 5 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-73492

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_ur…

    CVSS 2.3 · Low
    4 mentions
  • CVE-2026-73490

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its loc…

    CVSS 4.7 · Medium
    4 mentions
  • CVE-2026-73427

    Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-documen…

    CVSS 2.1 · Low
    4 mentions
  • CVE-2026-73422

    Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline st…

    CVSS 5.3 · Medium
    4 mentions
  • CVE-2026-73415

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/…

    CVSS 7.5 · High
    10 mentions
  • CVE-2026-73329

    CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by in…

    CVSS 9.2 · Critical
    3 mentions