CVE-2026-64638Patch

CRITICALCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 110 mentions across 17 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 37 signals
  • Patch or workaround mentioned in 58 signals
  • Technical details provided in 96 signals
  • Disclosure: 32 classified signals
  • Peaked 16d ago at 29 mentions (2026-08-07); latest day: 1
  • 110 total mentions across 17 days

Deep dive

Activity timeline110 mentions / 17d
07152229Mentions · 2026-08-07: 29Mentions · 2026-08-08: 15Mentions · 2026-08-09: 14Mentions · 2026-08-10: 10Mentions · 2026-08-11: 10Mentions · 2026-08-12: 7Mentions · 2026-08-13: 4Mentions · 2026-08-14: 8Mentions · 2026-08-15: 1Mentions · 2026-08-17: 4Mentions · 2026-08-18: 2Mentions · 2026-08-22: 1Mentions · 2026-08-26: 1Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1Mentions · 2026-09-12: 1Mentions · 2026-09-19: 1PoC Mentioned / Linked · 2026-08-07: 9PoC Mentioned / Linked · 2026-08-08: 6PoC Mentioned / Linked · 2026-08-09: 5PoC Mentioned / Linked · 2026-08-10: 4PoC Mentioned / Linked · 2026-08-11: 3PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-14: 5PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-22: 1PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-09-12: 1Exploit Tool / Code · 2026-08-07: 2Exploit Tool / Code · 2026-08-08: 1Exploit Tool / Code · 2026-08-09: 4Exploit Tool / Code · 2026-08-10: 2Exploit Tool / Code · 2026-08-11: 2Exploit Tool / Code · 2026-08-14: 2Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-08: 1Active Exploitation · 2026-08-09: 2Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-11: 1Patch / Workaround · 2026-08-07: 20Patch / Workaround · 2026-08-08: 9Patch / Workaround · 2026-08-09: 4Patch / Workaround · 2026-08-10: 6Patch / Workaround · 2026-08-11: 4Patch / Workaround · 2026-08-12: 5Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-14: 3Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-17: 3Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-07: 25Technical Details · 2026-08-08: 15Technical Details · 2026-08-09: 11Technical Details · 2026-08-10: 10Technical Details · 2026-08-11: 8Technical Details · 2026-08-12: 5Technical Details · 2026-08-13: 3Technical Details · 2026-08-14: 7Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 4Technical Details · 2026-08-18: 2Technical Details · 2026-08-22: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-12: 108-0708-0808-0908-1008-1108-1208-1308-1408-1508-1708-1808-2208-2608-2808-3009-1209-19
Signal classification6 categories
Patch
4239.3%
Disclosure
3229.9%
PoC
1917.8%
Exploit
54.7%
General
54.7%
Active Exploitation
43.7%
Referenced assets99 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-0729
Active Exploitation1Disclosure11Exploit1Patch12PoC4
2026-08-0815
Disclosure6Patch6PoC3
2026-08-0914
Active Exploitation2Disclosure1Exploit1General1Patch4PoC4
2026-08-1010
Active Exploitation1Disclosure3Exploit1Patch4PoC1
2026-08-1110
Disclosure1General3Patch4PoC2
2026-08-127
Disclosure1Patch5PoC1
2026-08-134
Disclosure2Patch1
2026-08-148
Disclosure1Exploit2Patch3PoC2
2026-08-151
Patch1
2026-08-174
Disclosure3Patch1
2026-08-182
Disclosure2
2026-08-221
Patch1
2026-08-261
PoC1
2026-08-281
Disclosure1
2026-08-301
General1
2026-09-121
PoC1
Full discourse20 posts
  • pwn.ai@pwn_ai
    PoC

    Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. https://pwn.ai/blog/xss2shell Please patch CVE-2026-64638 as soon as possible! https://t.co/0EKwgonspE

    Post summary

    The post announces a pre-authentication XSS-to-RCE vulnerability in WordPress, links to a proof of concept, and urges users to patch CVE‑2026‑64638.

    31202359657331.6M
    9.6K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    ‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version. XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution. Update your WordPress sites ASAP 🠖 https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

    Post summary

    A new pre‑auth cross‑site scripting vulnerability (CVE-2026-64638) that can lead to PHP code execution on all WordPress versions has been discovered, and users are urged to update their sites immediately.

    1724318976396109.0K
    2.4M followersView on X
  • Dark Web Informer@DarkWebInformer
    Patch

    🚨 WordPress patches XSS2Shell flaw that could lead to server code execution CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen. The XSS itself requires no account. Researchers at http://pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page. A successful chain could potentially allow attackers to: • Create API credentials • Gain authenticated REST access • Upload malicious plugin files • Execute PHP on the server • Access WordPress secrets and database credentials WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch. NHS England says exploitation is likely following the release of technical details and a PoC. WordPress has not reported confirmed exploitation in the wild as of August 7. Update immediately.

    Post summary

    CVE-2026-64638 is a pre‑authentication XSS vulnerability in WordPress with a publicly released PoC and recent patch, but no confirmed wild exploitation yet.

    42501545617.1K
    238.7K followersView on X
  • 辻 伸弘 (nobuhiro tsuji)@ntsuji
    Disclosure

    🚨 WordPressで新たなRCE攻撃チェーン「XSS2Shell」が公開 先月話題となったwp2shell(REST API認可不備+SQLi)に続き、今度は、ログイン画面の反射型XSS(CVE-2026-64638)を起点にサーバの乗っ取りにまで至る攻撃チェーン「XSS2Shell」が公開。 両者の違いは次のとおりです。 ✅ wp2shell ・認証不要 ・ユーザー操作不要 ・REST APIの認可不備+SQLiを悪用 ・外部から直接RCEが可能 ✅ XSS2Shell ・認証不要 ・管理者による細工したURLの閲覧が必要 ・ログイン画面の反射型XSSを悪用 ・管理者権限で悪意あるプラグインを導入しRCE XSS2Shellは、ユーザ操作が必要なため、wp2shellほど深刻な攻撃の成立条件ではありませんが、管理者権限でのログイン済みのユーザが細工されたURLを開くことでサーバ侵害につながる点には注意が必要です。

    Post summary

    The post discloses a new WordPress RCE chain, XSS2Shell, exploiting CVE-2026-64638 reflected XSS on the login screen, detailing the attack steps but offers no PoC, exploit code, or patch information.

    019368358.6K
    28.9K followersView on X
  • 𝐑𝐀𝐢𝐡𝐚𝐧@zapstiko
    PoC

    XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638) #bugbounty #bugbountytips #cve #rce https://beralock.com/blog/xss-to-shell-msj9h043

    Post summary

    The blog post announces a new WordPress vulnerability (CVE‑2026‑64638) that chains a pre‑authentication XSS to remote code execution, and includes a PoC demonstrating the attack.

    18065394.8K
    7.7K followersView on X
  • XSS Payloads@XssPayloads
    PoC

    XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638) A good XSS use case by Nigusu Kasahun https://pwn.ai/blog/xss2shell

    Post summary

    The text announces a proof-of-concept chain for WordPress CVE-2026-64638, demonstrating how a pre‑authenticated XSS can be leveraged to achieve remote code execution, as detailed in the linked pwn.ai blog.

    05055344.7K
    55.7K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚡ ICYMI: One click from a logged-in #WordPress admin can trigger a chain from pre-auth XSS to PHP code execution. CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication. Patch now: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

    Post summary

    CVE-2026-64638 is a pre‑authentication XSS in WordPress that can be exploited to execute PHP code, and a patch is available via the provided advisory link.

    316151924.5K
    2.4M followersView on X
  • Sekurak@Sekurak
    Disclosure

    ⚠️ Masz WordPressa? Aktualizuj go teraz. Jedna spacja po znaku < wystarczyła, by strip_tags() i KSES inaczej zinterpretowały ten sam HTML. Efekt? CVE-2026-64638: pre-auth XSS, który przy ataku na zalogowanego administratora można doprowadzić aż do RCE. Jak działa łańcuch XSS2Shell? 👇 https://sekurak.pl/roznica-w-parsowaniu-html-moze-doprowadzic-do-rce-w-wordpressie/

    Post summary

    The post announces CVE-2026‑64638, a pre‑authentication XSS in WordPress that can evolve into RCE, and urges users to update their installations, with a link to a detailed chain explanation.

    1405398.2K
    44.6K followersView on X
  • Professor Larry Densel@luckyhacker43
    Disclosure

    💀 CVE-2026-64638: XSS2Shell (WP login XSS to RCE)WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Detection: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-64638.yaml Join team 👉 https://t.me/luckyhacker42 https://t.co/LKN9qoj56r

    Post summary

    The post announces the new CVE-2026-64638 (a WordPress login XSS leading to RCE), provides a detection template, and gives basic technical details, but does not mention exploitation, patches, or false‑positive status.

    47035181.8K
    4.6K followersView on X
  • NITDA Nigeria@NITDANigeria
    Patch

    WordPress users and administrators, take note! 🚨 http://CERT.ng issues an advisory on the critical pre-authentication XSS vulnerability CVE-2026-64638, which could allow attackers to execute malicious PHP code without authentication. Update WordPress Core to version 7.0.3 and implement recommended security measures to protect your website.

    Post summary

    An advisory highlights a critical pre-authentication XSS vulnerability in WordPress (CVE-2026-64638) and advises users to update to WordPress Core 7.0.3 to mitigate the risk.

    01304125.8K
    316.9K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: WordPress has patched CVE-2026-64638, a pre-auth XSS-to-RCE chain affecting every WordPress version ever released. The flaw allowed attackers to turn a crafted username into executable code, ultimately achieving PHP code execution on the server. The issue was discovered using open-weight LLMs and is fixed in WordPress 7.0.3. #WordPress #CVE #RCE #XSS #CyberSecurity #WebSecurity #Infosec

    Post summary

    WordPress has issued a patch for CVE‑2026‑64638, a pre‑authentication XSS‑to‑RCE vulnerability affecting all versions, with the fix available in WordPress 7.0.3. The flaw allows attackers to use a crafted username to execute arbitrary PHP code.

    3803833.7K
    1.5K followersView on X
  • Bug bounty wizard@bugbountywizard
    Disclosure

    XSS2Shell: CVE-2026-64638 — From WordPress Pre-Auth XSS to RCE — by CoffSec https://coffsec.medium.com/xss2shell-cve-2026-64638-from-wordpress-pre-auth-xss-to-rce-93f85d23e285 Join us on Telegram: https://t.me/bugbountywizard #bugbounty #bugbountytips #bugbountytip

    Post summary

    The text announces CVE-2026-64638, detailing its progression from a pre‑authentication XSS vulnerability in WordPress to a remote code execution flaw, with PoC information implied via the linked Medium article.

    05026121.5K
    2.2K followersView on X
  • Brut 🇮🇳@wtf_yodhha
    Exploit

    🚨CVE-2026-64638: XSS2Shell (WP login XSS to RCE)WordPress is vulnerable to a preauth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker ✅Download Tools https://t.me/brutsecurity/2893 #CyberSecurity #BugBounty https://t.co/BOhYy8BaPq

    Post summary

    CVE‑2026‑64638 is a preauthentication XSS vulnerability in WordPress that can be leveraged to achieve RCE, and an exploit tool is linked for download, though no active exploitation or patch information is provided.

    11026101.9K
    7.9K followersView on X
  • Bug Bounty Insights 🪄@bbr_bug
    PoC

    WordPress login XSS via sanitizer disagreement (CVE-2026-64638) `&lt;b&gt;` gets stripped but `&lt; b&gt;` passes the first sanitizer Second normalizes `&lt; b&gt;` back to valid HTML Chain: DOM clobbering + JSONP = exec on login page https://learn.uphack.io/lab/xss2shell-wordpress-login

    Post summary

    The post highlights a WordPress login XSS vulnerability (CVE‑2026‑64638) with technical details on sanitizer disagreement and a chain for execution, linked to a lab PoC. No active exploit or patch is mentioned.

    0302491.2K
    5.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-64638 - high 🚨 WordPress Core &lt; 7.0.3 - Preauth Reflected XSS (XSS2Shell) &gt; Pre-authentication reflected XSS in WordPress wp-login.php (CVE-2026-64638). The flaw... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-64638 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a high‑severity reflected XSS vulnerability in WordPress wp‑login.php and links to a library entry that likely contains a PoC or detection template; no active exploitation, patches, or false‑positive claims are mentioned.

    0202091.1K
    1.3K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now. #WordPress #XSS #RCE #CVE #CyberSecurity http://securityonline.info/wordpress-security-update-7-0-3/

    Post summary

    WordPress version 7.0.3 includes a fix for CVE‑2026‑64638, a pre‑authentication XSS that could lead to remote code execution (CVSS 8.9). Users are urged to update immediately.

    0701661.1K
    13.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 WordPress Core'da kritik güvenlik açığı ortaya çıktı ! CVE-2026-64638 (XSS2Shell) 👉 Etkilenenler: Tüm WordPress sürümleri (4.7'den 7.0.2'ye kadar). Yani neredeyse internetteki her WordPress sitesi etkileniyor. 👉 Nasıl istismar ediliyor? • Login ekranında pre-auth (oturum gerektirmeyen) Reflected XSS açığı var. • Saldırgan, özel hazırlanmış bir kullanıcı adı ile login sayfasında JavaScript çalıştırabiliyor. • Bu XSS, oturum açık bir Yönetici (Administrator) ile etkileşim kurulursa (tek tıklama) Application Password oluşturulmasına, REST API üzerinden yetki alınmasına ve kötü amaçlı eklenti yüklenmesine kadar gidebiliyor. • Sonuç: PHP kod çalıştırma (RCE) mümkün hale geliyor. Bu zincire XSS2Shell deniyor. Doğrudan "pre-auth RCE" değil, admin etkileşimi ve sosyal mühendislik gerektiriyor. 👉 Yama: WordPress 7.0.3 ile bu açık kapatıldı (6 Ağustos 2026). Desteklenen tüm eski sürümler için de güvenlik güncellemesi yayınlandı (6.9.6, 6.8.7 … 4.7.34'e kadar). 🚨 Ne yapmalısınız? Hemen WordPress'inizi 7.0.3 veya ilgili yamalı sürüme güncelleyin! Otomatik güncelleme açıksa kısa sürede gelecektir. Resmi duyuru: https://wordpress.org/news/2026/08/wordpress-7-0-3-release/ Write-up: https://pwn.ai/blog/xss2shell

    Post summary

    WordPress Core CVE-2026-64638 (XSS2Shell) is disclosed as a pre‑authentication reflected XSS leading to RCE via admin interaction; patches issued in WP 7.0.3 and earlier releases, with a write‑up available.

    1111967.0K
    2.3K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Patch

    昨夜リツイートしたWordPress Core の CVE-2026-64638(XSS2Shell)の件です。 調べると、wp2shellのおかげでCoreに注意が払われる中で発見された新たな脆弱性らしい。 とにかく、7.0.3(旧系列は6.9.6等の修正版)への更新がまだの方は早急に。 wp2shellを放置していたサイトが被害に遭ったと思われる報告も見かけます。 #WordPress #XSS2Shell #セキュリティ #AppSec

    Post summary

    The Twitter post discusses the newly discovered CVE-2026-64638, an XSS-to-shell vulnerability in WordPress Core found via wp2shell; it urges users to upgrade immediately and notes reports of active exploitation.

    0411342.8K
    856 followersView on X
  • Dipak Gajjar@dipakcgajjar
    Patch

    Your WordPress site could get hijacked without a password. A nasty login-page bug (CVE-2026-64638) let attackers run code just by tricking an admin into clicking a link. It's already patched in latest WordPress release -- update now if you haven't. https://t.co/7Va7ROmKoB

    Post summary

    The CVE‑2026‑64638 login‑page bug that lets attackers run code via a link is now fixed in the latest WordPress release; users are urged to update.

    130102545
    5.1K followersView on X
  • Meisam@maanimis
    PoC

    🔸CVE-2026-64638 (XSS2Shell) بازم cve با high severity در وردپرس! از XSS تا RCE ! ورژن‌هایی که اسیب‌پذیر هستن توی عکس هستش: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf جزییات: https://pwn.ai/blog/xss2shell https://t.co/yAapWhGd5V

    Post summary

    CVE-2026-64638 is a high‑severity XSS‑to‑RCE vulnerability in WordPress; a Proof of Concept is shared via a blog post and advisory link, but there is no evidence of active exploitation.

    0011221.6K
    737 followersView on X

Explore more