securityonline.info 8/7/2026, 3:41:34 AM · external

CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution

CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution
CyberSIXT Evidence Panel
Primary Source wordpress.org
CISA KEV Not in KEV
Patch Patch Status Unknown

WORDPRESS 7.0.3 has been released as a crucial security update addressing multiple vulnerabilities, most notably CVE-2026-64638, a pre-authentication cross-site scripting (XSS) flaw that could lead to remote code execution. This vulnerability has a high severity score of 8.9 and allows attackers to exploit it without prior authentication, thereby affecting a large number of websites. The update also fixes several other vulnerabilities, including stored XSS issues and privilege escalation bugs. Users are urged to update to version 7.0.3 immediately to safeguard their sites, as there are no confirmed exploitations in the wild yet.

View Primary Source Via securityonline.info

Article by CyberSIXT