Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-64638

Опубликовано: 07 авг. 2026
Источник: debian
EPSS Низкий

Описание

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed7.0.3+dfsg1-1package

Примечания

  • https://wordpress.org/news/2026/08/wordpress-7-0-3-release/

  • https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf

EPSS

Процентиль: 52%
0.00766
Низкий

Связанные уязвимости

ubuntu
2 дня назад

[Unknown description]

nvd
1 день назад

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

EPSS

Процентиль: 52%
0.00766
Низкий