8.9

CVE-2026-64638 (XSS2Shell)

Medienbericht

Pre-auth reflected XSS on login screen with potential to lead to PHP code execution

WordPress Core <= 7.0.2 - Unauthenticated Reflected Cross-Site Scripting via log Parameter

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.

Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.

This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
WordPress Core: Install latest version
WordPress: Update to one of the following versions, or a newer patched version: 4.7.34, 4.8.29, 4.9.30, 5.0.26, 5.1.23, 5.2.25, 5.3.22, 5.4.20, 5.5.19, 5.6.18, 5.7.16, 5.8.14, 5.9.14, 6.0.13, 6.1.11, 6.2.10, 6.3.9, 6.4.9, 6.5.9, 6.6.6, 6.7.6, 6.8.7, 6.9.6, 7.0.3
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWordPress
Produkt WordPress
Default Statusaffected
Version 0
Version < 7.0.3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
System
Produkt WordPress Core
Version >= 7.0.0, < 7.0.3
Version >= 6.9.0, < 6.9.6
Version >= 6.8.0, < 6.8.7
Version >= 6.7.0, < 6.7.6
Version >= 6.6.0, < 6.6.6
Version >= 6.5.0, < 6.5.9
Version >= 6.4.0, < 6.4.9
Version >= 6.3.0, < 6.3.9
Version >= 6.2.0, < 6.2.10
Version >= 6.1.0, < 6.1.11
Version >= 6.0.0, < 6.0.13
Version >= 5.9.0, < 5.9.14
Version >= 5.8.0, < 5.8.14
Version >= 5.7.0, < 5.7.16
Version >= 5.6.0, < 5.6.18
Version >= 5.5.0, < 5.5.19
Version >= 5.4.0, < 5.4.20
Version >= 5.3.0, < 5.3.22
Version >= 5.2.0, < 5.2.25
Version >= 5.1.0, < 5.1.23
Version >= 5.0.0, < 5.0.26
Version >= 4.9.0, < 4.9.30
Version >= 4.8.0, < 4.8.29
Version >= 4.7.0, < 4.7.34
System
Produkt WordPress Core
Version >= 7.0.0, < 7.0.3
Version >= 6.9.0, < 6.9.6
Version >= 6.8.0, < 6.8.7
Version >= 6.7.0, < 6.7.6
Version >= 6.6.0, < 6.6.6
Version >= 6.5.0, < 6.5.9
Version >= 6.4.0, < 6.4.9
Version >= 6.3.0, < 6.3.9
Version >= 6.2.0, < 6.2.10
Version >= 6.1.0, < 6.1.11
Version >= 6.0.0, < 6.0.13
Version >= 5.9.0, < 5.9.14
Version >= 5.8.0, < 5.8.14
Version >= 5.7.0, < 5.7.16
Version >= 5.6.0, < 5.6.18
Version >= 5.5.0, < 5.5.19
Version >= 5.4.0, < 5.4.20
Version >= 5.3.0, < 5.3.22
Version >= 5.2.0, < 5.2.25
Version >= 5.1.0, < 5.1.23
Version >= 5.0.0, < 5.0.26
Version >= 4.9.0, < 4.9.30
Version >= 4.8.0, < 4.8.29
Version >= 4.7.0, < 4.7.34
SystemWordPress Core
Produkt WordPress
Version 4.7.0-4.7.33
Version 4.8.0-4.8.28
Version 4.9.0-4.9.29
Version 5.0.0-5.0.25
Version 5.1.0-5.1.22
Version 5.2.0-5.2.24
Version 5.3.0-5.3.21
Version 5.4.0-5.4.19
Version 5.5.0-5.5.18
Version 5.6.0-5.6.17
Version 5.7.0-5.7.15
Version 5.8.0-5.8.13
Version 5.9.0-5.9.13
Version 6.0.0-6.0.12
Version 6.1.0-6.1.10
Version 6.2.0-6.2.9
Version 6.3.0-6.3.8
Version 6.4.0-6.4.8
Version 6.5.0-6.5.8
Version 6.6.0-6.6.5
Version 6.7.0-6.7.5
Version 6.8.0-6.8.6
Version 6.9.0-6.9.5
Version 7.0.0-7.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.563
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HackerOne 8.9 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
12.08.2026 11:55
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
11.08.2026 08:24
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.08.2026 18:54
https://hackerone.com/reports/3877102
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/278da117-fe04-45d6-86d4-e71fe6536032
Third Party Advisory