{"id":588129,"date":"2026-08-09T17:14:15","date_gmt":"2026-08-09T17:14:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/588129\/"},"modified":"2026-08-09T17:14:15","modified_gmt":"2026-08-09T17:14:15","slug":"cve-2026-64638-critical-pre-auth-xss-vulnerability-in-wordpress-allows-remote-code-execution-update-to-7-0-3-urgently-rescana","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/588129\/","title":{"rendered":"CVE-2026-64638: Critical Pre-Auth XSS Vulnerability in WordPress Allows Remote Code Execution \u2013 Update to 7.0.3 Urgently \u2013 Rescana"},"content":{"rendered":"<p>Executive Summary<\/p>\n<p>A critical vulnerability has been identified in WordPress\u2014specifically, a pre-authentication reflected Cross-Site Scripting (XSS) flaw tracked as CVE-2026-64638. This vulnerability, present in all WordPress\u00a0versions up to 7.0.2, enables unauthenticated attackers to inject and execute JavaScript on the login page. When combined with social engineering, this XSS can escalate to remote PHP code execution (RCE), potentially resulting in full compromise of the affected site. Immediate patching to WordPress 7.0.3\u00a0or the latest available security release is strongly advised. While public technical details and proof-of-concept code are available, there is currently no confirmed exploitation in the wild, and this CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.<\/p>\n<p>Technical Information<\/p>\n<p>CVE-2026-64638\u00a0is a pre-auth reflected XSS vulnerability that can be leveraged to achieve PHP code execution on WordPress\u00a0servers. The flaw arises from improper sanitization of the username field on failed login attempts. Attackers can craft a username containing a &lt; character followed by whitespace, which bypasses the sanitize_user() and wp_strip_all_tags() functions due to the behavior of PHP&#8217;s strip_tags(). The input is then processed by wp_kses_post(), which interprets it as permitted HTML, resulting in attacker-controlled DOM elements being rendered on the login error page.<\/p>\n<p>The attack chain, dubbed XSS2Shell, proceeds as follows: The attacker injects malicious JavaScript via the login page. The page loads user-profile.js for password resets, and the attacker can manipulate missing elements and the undefined ajaxurl variable through the injected DOM. This enables the execution of attacker-controlled JavaScript, which can make same-origin REST API requests.<\/p>\n<p>If a logged-in administrator visits a malicious page, the XSS can be used to exploit the WordPress REST JSONP\u00a0endpoint, execute JavaScript in the site&#8217;s origin, and leverage the Application Password approval flow to create a new API credential. With this credential, the attacker can publish a page containing further malicious JavaScript, obtain a plugin-upload nonce, and upload a ZIP file containing a PHP webshell or backdoor. The PHP file can be executed directly, even if the plugin is not activated.<\/p>\n<p>The impact of successful exploitation is severe: Attackers can gain full control over the WordPress\u00a0site, extract database credentials from wp-config.php, create persistent admin users, modify site content, exfiltrate files and secrets, and execute arbitrary OS commands with the privileges of the PHP worker process.<\/p>\n<p>Exploitation in the Wild<\/p>\n<p>As of August 7, 2026, there are no confirmed reports of in-the-wild exploitation of CVE-2026-64638. However, public technical details and proof-of-concept exploits are available from sources such as pwn.ai\u00a0and The Hacker News, significantly increasing the risk of imminent exploitation. The attack does not require authentication for the initial XSS, but escalation to RCE depends on social engineering\u2014specifically, tricking a logged-in administrator into visiting a malicious page. No sector, country, or organization-specific targeting has been observed, and no ransomware or criminal campaigns have been attributed to this vulnerability.<\/p>\n<p>Threat Actor Profile<\/p>\n<p>There is currently no evidence that any Advanced Persistent Threat (APT) groups or criminal threat actors are exploiting CVE-2026-64638. Open sources, including MITRE and major threat intelligence platforms, have not reported any targeted campaigns or group attributions related to this vulnerability as of the time of writing.<\/p>\n<p>Technical Analysis of Malware\/TTPs<\/p>\n<p>All versions of WordPress\u00a0prior to 7.0.3 are affected by CVE-2026-64638. This includes all major and minor releases from the initial release up to and including 7.0.2. The patch has been backported to the 4.7 branch and later, but older versions (4.6 and below) are no longer supported and remain vulnerable. The fixed version is WordPress 7.0.3\u00a0and corresponding backported security releases for supported branches.<\/p>\n<p>Exploitation in the Wild<\/p>\n<p>As of August 7, 2026, there are no confirmed reports of in-the-wild exploitation of CVE-2026-64638. However, public technical details and proof-of-concept exploits are available from sources such as pwn.ai\u00a0and The Hacker News, significantly increasing the risk of imminent exploitation. The attack does not require authentication for the initial XSS, but escalation to RCE depends on social engineering\u2014specifically, tricking a logged-in administrator into visiting a malicious page. No sector, country, or organization-specific targeting has been observed, and no ransomware or criminal campaigns have been attributed to this vulnerability.<\/p>\n<p>Victimology and Targeting<\/p>\n<p>There is currently no evidence that any Advanced Persistent Threat (APT) groups or criminal threat actors are exploiting CVE-2026-64638. Open sources, including MITRE and major threat intelligence platforms, have not reported any targeted campaigns or group attributions related to this vulnerability as of the time of writing.<\/p>\n<p>Mitigation and Countermeasures<\/p>\n<p>The most effective mitigation is to upgrade immediately to WordPress 7.0.3\u00a0or the latest available security release. Ensure that automatic background updates are enabled to receive future patches promptly. Administrators should monitor logs for suspicious login attempts, unexpected Application Password creation, and unauthorized plugin uploads. Restrict admin access to trusted networks and educate administrators about the risks of social engineering and phishing. Review all custom plugins and themes to ensure they do not bypass WordPress\u00a0sanitization routines.<\/p>\n<p>References<\/p>\n<p style=\"text-align:left;hyphens:none;word-break:break-word;\"><a href=\"https:\/\/thehackernews.com\/2026\/08\/new-wordpress-pre-auth-xss-could-lead.html\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">The Hacker News: New WordPress Pre-Auth XSS Could Lead to PHP Code Execution<\/a>, <a href=\"https:\/\/forum.ksec.co.uk\/t\/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap\/16865\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">KSEC Community Forum<\/a>, <a href=\"https:\/\/www.reddit.com\/r\/SecOpsDaily\/comments\/1vi1o2j\/new_wordpress_preauth_xss_could_lead_to_php_code\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Reddit: r\/SecOpsDaily<\/a>, <a href=\"https:\/\/www.linkedin.com\/posts\/alexandre-blanc-cyber-security-88569022_new-wordpress-pre-auth-xss-could-lead-to-activity-7491500802247708672-5DvO\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">LinkedIn: a cyber security professional<\/a>, <a href=\"https:\/\/wordpress.org\/news\/category\/security\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">WordPress Security Advisory<\/a>, <a href=\"https:\/\/pwn.ai\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">pwn.ai Research<\/a>, <a href=\"https:\/\/attack.mitre.org\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">MITRE ATT&amp;CK Framework<\/a><\/p>\n<p>About Rescana<\/p>\n<p>Rescana\u00a0provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their digital supply chain. Our platform delivers actionable intelligence and automated workflows to help you stay ahead of emerging threats. We are happy to answer any questions at info@rescana.com.<\/p>\n","protected":false},"excerpt":{"rendered":"Executive Summary A critical vulnerability has been identified in WordPress\u2014specifically, a pre-authentication reflected Cross-Site Scripting (XSS) flaw tracked&hellip;\n","protected":false},"author":2,"featured_media":588130,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61,60,80],"class_list":["post-588129","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/588129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=588129"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/588129\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/588130"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=588129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=588129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=588129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}