MIRAGE
Threat IntelligenceCVEs › CVE-2026-64638

CVE-2026-64638 — exposed on the internet

New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?

Internet exposure observed by OffSeq scans · last 30 days

9
Exposed hosts
8.9
CVSS
0.9%
EPSS

Found on 9 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-64638

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date.

OffSeq internet scanning found CVE-2026-64638 on 9 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

wordpress

Open the live CVE-2026-64638 view →

References