Critical WordPress Core Vulnerability (CVE-2026-64638) Puts Over 500 Million Sites at Risk

A pre-authentication chain leading from Cross-Site Scripting (XSS) to code execution has been discovered in WordPress Core, affecting versions since 4.7 and impacting virtually all WordPress sites. The vulnerability, identified as CVE-2026-64638 with a CVSSv4 score of 8.9, exploits a discrepancy in sanitization functions to inject active HTML into the login screen without requiring an account. A public Python exploit is available, increasing the risk to unpatched installations. WordPress released a fix on August 6 in version 7.0.3.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai