Feed/CVE-2026-64638
CVE-2026-64638

CVE-2026-64638

Published Aug 7, 2026·Updated Aug 7, 2026

NVD Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Public Exploits & PoCs18 found

PoC: XSS2Shell-CVE-2026-64638

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).

2

PoC: Cve-2026-64638

Educational use only!

1

PoC: CVE-2026-64638

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing

1

PoC: CVE-2026-64638

CVE-2026-64638 (XSS2shell) POC.

1

PoC: CVE-2026-64638

CVE-2026-64638

1

[POC] CVE-2026-64638 — XSS2Shell

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

[POC] CVE-2026-64638 — POC-WP-XSS2Shell-CVE-2026-64638

PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.

[POC] CVE-2026-64638 — CVE-2026-64638-PoC

XSS2Shell (CVE-2026-64638) PoC — WordPress pre-auth XSS to RCE chain

PoC: xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

PoC: CVEX2SHEL

CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.

PoC: xss2shell

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

PoC: XSS2Shell

XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.

PoC: XSS2Shell-CVE-2026-64638

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).

PoC: CVE-2026-64638-PoC-Exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd

PoC: CVE-2026-64638-POC

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

PoC: CVE-2026-64638-WordPress-Core-XSS2Shell

Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.

PoC: CVE-2026-64638

CVE-2026-64638

PoC: CVE-2026-64638

CVE-2026-64638 - Draft or TODO

Community Discussion

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free