CVE-CVE-2026-64638
Severity
UNKNOWN
CVSS Score
0.0
Description
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and...
PoCs for CVE-CVE-2026-64638
CVE-2026-64638-PoC-XSS2Shell-
RCE
Python
13
Boreas37
2026-08-07
XSS2Shell-CVE-2026-64638
RCE
Python
4
Linuxhackingid-official
2026-08-07
CVE-2026-64638-PoC-Exploit
General
Python
1
tc4dy
2026-08-08
CVE-2026-64638
XSS
HTML
1
4minx
2026-08-08
poc-CVE-2026-64638-
General
Python
0
mohwahyudi
2026-08-08
CVE-2026-64638-POC
RCE
Python
0
imbas007
2026-08-08
xss2shell
XSS
Python
0
0xlipon
2026-08-09
CVE-2026-64638-XSS-to-Shell-PoC
XSS
Python
0
eh-amish
2026-08-09