8.9
CVE-2026-64638 (XSS2Shell)
- EPSS 0.89%
- Veröffentlicht 07.08.2026 18:17:20
- Zuletzt bearbeitet 07.08.2026 19:18:51
- CVE-Watchlists
- Unerledigt
Pre-auth reflected XSS on login screen with potential to lead to PHP code execution
WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
WordPress Core: Install latest version
WordPress: Update to one of the following versions, or a newer patched version: 4.7.34, 4.8.29, 4.9.30, 5.0.26, 5.1.23, 5.2.25, 5.3.22, 5.4.20, 5.5.19, 5.6.18, 5.7.16, 5.8.14, 5.9.14, 6.0.13, 6.1.11, 6.2.10, 6.3.9, 6.4.9, 6.5.9, 6.6.6, 6.7.6, 6.8.7, 6.9.6, 7.0.3
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWordPress
≫
Produkt
WordPress
Default Statusaffected
Version
0
Version <
7.0.3
Status
unaffected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
System
≫
Produkt
WordPress Core
Version
>= 7.0.0, < 7.0.3
Version
>= 6.9.0, < 6.9.6
Version
>= 6.8.0, < 6.8.7
Version
>= 6.7.0, < 6.7.6
Version
>= 6.6.0, < 6.6.6
Version
>= 6.5.0, < 6.5.9
Version
>= 6.4.0, < 6.4.9
Version
>= 6.3.0, < 6.3.9
Version
>= 6.2.0, < 6.2.10
Version
>= 6.1.0, < 6.1.11
Version
>= 6.0.0, < 6.0.13
Version
>= 5.9.0, < 5.9.14
Version
>= 5.8.0, < 5.8.14
Version
>= 5.7.0, < 5.7.16
Version
>= 5.6.0, < 5.6.18
Version
>= 5.5.0, < 5.5.19
Version
>= 5.4.0, < 5.4.20
Version
>= 5.3.0, < 5.3.22
Version
>= 5.2.0, < 5.2.25
Version
>= 5.1.0, < 5.1.23
Version
>= 5.0.0, < 5.0.26
Version
>= 4.9.0, < 4.9.30
Version
>= 4.8.0, < 4.8.29
Version
>= 4.7.0, < 4.7.34
System
≫
Produkt
WordPress Core
Version
>= 7.0.0, < 7.0.3
Version
>= 6.9.0, < 6.9.6
Version
>= 6.8.0, < 6.8.7
Version
>= 6.7.0, < 6.7.6
Version
>= 6.6.0, < 6.6.6
Version
>= 6.5.0, < 6.5.9
Version
>= 6.4.0, < 6.4.9
Version
>= 6.3.0, < 6.3.9
Version
>= 6.2.0, < 6.2.10
Version
>= 6.1.0, < 6.1.11
Version
>= 6.0.0, < 6.0.13
Version
>= 5.9.0, < 5.9.14
Version
>= 5.8.0, < 5.8.14
Version
>= 5.7.0, < 5.7.16
Version
>= 5.6.0, < 5.6.18
Version
>= 5.5.0, < 5.5.19
Version
>= 5.4.0, < 5.4.20
Version
>= 5.3.0, < 5.3.22
Version
>= 5.2.0, < 5.2.25
Version
>= 5.1.0, < 5.1.23
Version
>= 5.0.0, < 5.0.26
Version
>= 4.9.0, < 4.9.30
Version
>= 4.8.0, < 4.8.29
Version
>= 4.7.0, < 4.7.34
SystemWordPress Core
≫
Produkt
WordPress
Version
4.7.0-4.7.33
Version
4.8.0-4.8.28
Version
4.9.0-4.9.29
Version
5.0.0-5.0.25
Version
5.1.0-5.1.22
Version
5.2.0-5.2.24
Version
5.3.0-5.3.21
Version
5.4.0-5.4.19
Version
5.5.0-5.5.18
Version
5.6.0-5.6.17
Version
5.7.0-5.7.15
Version
5.8.0-5.8.13
Version
5.9.0-5.9.13
Version
6.0.0-6.0.12
Version
6.1.0-6.1.10
Version
6.2.0-6.2.9
Version
6.3.0-6.3.8
Version
6.4.0-6.4.8
Version
6.5.0-6.5.8
Version
6.6.0-6.6.5
Version
6.7.0-6.7.5
Version
6.8.0-6.8.6
Version
6.9.0-6.9.5
Version
7.0.0-7.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.563 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HackerOne | 8.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://hackerone.com/reports/3877102
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
https://www.wordfence.com/threat-intel/vulnerabilities/id/278da117-fe04-45d6-86d4-e71fe6536032