S4E just found a high top 10 tcp port service scan
high·Web Vulnerabilities·Updated Aug 7, 2026

CVE-2026-64638 Scanner

CVE-2026-64638 Scanner - Cross-Site Scripting (XSS) vulnerability in WordPress

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-64638
8.9
CVSShigh
Exploitable remotely over the internet · no authentication required.

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Attack Vector
Network
Privileges Req.
None
User Interaction
A
Affected
WordPressby WordPress
AFFECTED< 7.0.3SAFE ✓≥ 7.0.3
Updated Aug 19, 2026View on NVD →
Detail

WordPress is a popular content management system widely used for creating websites and blogs. Developed by Automattic, it powers a significant portion of websites worldwide due to its flexibility and extensive plugin ecosystem. Users from individual bloggers to large corporations utilize WordPress for its ease of use and powerful features. The platform allows for significant customization, supporting a wide range of themes and plugins to extend functionality. As an open-source platform, WordPress is continually updated and improved by a large community of developers and contributors. However, due to its widespread use, WordPress is also a common target for cybersecurity threats.

The vulnerability addressed by this scanner is a pre-authentication reflected XSS, allowing attackers to inject and execute malicious scripts. It exploits a parser differential issue between PHP's strip_tags() and WordPress's KSES function. By inserting whitespace after "<" tags, attackers can bypass the strip_tags() function, creating valid HTML elements in KSES. These elements then execute JavaScript code automatically via user-profile.js, leading to a security breach without requiring user interaction. This vulnerability affects all WordPress versions prior to 7.0.3, urging users to update immediately.

Technical details reveal that the vulnerability resides in the wp-login.php file, where improper handling of input allows for reflected XSS attacks. Specifically, the flaw targets how input data is parsed and sanitized, creating an entry point for attackers to inject code. The attack vector comes from crafted parameters within HTTP POST requests to wp-login.php. Successful exploitation can trigger JavaScript execution via DOM elements like manipulated by attackers. The exploitation relies on user interaction with specially crafted outputs but can be automated in numerous attack scenarios.

The exploitation of this XSS vulnerability can have several severe effects. Attackers can gain unauthorized access to sensitive information, manipulate web sessions, or carry out further attacks using the compromised WordPress site as a base. Additionally, remote code execution could be achieved in the context of affected users, leading to full site compromise. If not addressed, this vulnerability could result in data breaches, loss of user trust, and potential defacement or service disruption of WordPress websites. Preventing such outcomes necessitates a prompt update to WordPress 7.0.3 or applying relevant security patches.

REFERENCES

Solution Advice
  • Upgrade WordPress to version 7.0.3 or later to ensure the vulnerability is patched.
  • Consider implementing a web application firewall (WAF) to filter out malicious requests.
  • Regularly monitor logs and site activity for any unusual behavior indicative of exploitation attempts.
  • Educate users about safe web interaction practices to reduce the risk of introducing malicious inputs.
  • Consider using plugins that enhance security by offering additional sanitization features.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.