Critical WordPress XSS2Shell Vulnerability (CVE-2026-64638) Actively Exploited, Affecting Over 500 Million Sites

A critical pre-authentication XSS to code execution vulnerability (CVE-2026-64638) in WordPress Core, present since version 4.7, is being actively exploited. This flaw, which affects over 43% of the web, allows attackers to inject active HTML into the login screen without requiring an account or user interaction. A public Python exploit is available, urging immediate updates to WordPress version 7.0.3 or the backport to branch 4.7.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai