WordPress Security Update Advisory (CVE-2026-64638)

WordPress Security Update Advisory (CVE-2026-64638)

Overview


A security update has been released to address a vulnerability in WordPress. This vulnerability, identified as CVE-2026-64638, is a pre-authentication reflected cross-site scripting (XSS) vulnerability—a type of vulnerability that tricks users into executing malicious scripts—occurring on the WordPress login screen.

Affected Versions


The affected WordPress versions are as follows:

  • 4.7.0 Through 4.7.33.
  • 4.8.0 Through 4.8.28.
  • 4.9.0 Through 4.9.29.
  • 5.0.0 Through 5.0.25.
  • 5.1.0 Through 5.1.22.
  • 5.2.0 Through 5.2.24.
  • 5.3.0 Or higher, 5.3.21 Or lower.
  • 5.4.0 Or higher, 5.4.19 Or lower.
  • 5.5.0 Or higher, 5.5.18 Or lower.
  • 5.6.0 Or higher, 5.6.17 Or lower.
  • 5.7.0 Or higher, 5.7.15 Or lower.
  • 5.8.0 Or higher, 5.8.13 Or lower.
  • 5.9.0 Or higher, 5.9.13 Or lower.
  • 6.0.0 Or higher, 6.0.12 Or lower.
  • 6.1.0 Or higher, 6.1.10 Or lower.
  • 6.2.0 Or higher, 6.2.9 Or lower.
  • 6.3.0 Or higher, 6.3.8 Or lower.
  • 6.4.0 Or higher, 6.4.8 Or lower.
  • 6.5.0 Or higher, 6.5.8 Or lower.
  • 6.6.0 Or higher, 6.6.5 Or lower.
  • 6.7.0 Or higher, 6.7.5 Or lower.
  • 6.8.0 Or higher, 6.8.6 Or lower.
  • 6.9.0 Or higher, 6.9.5 Or lower.
  • 7.0.0 Or higher, 7.0.2 Or lower.

Action Required


A Vulnerability Patch has been provided via the latest update. The patch versions listed in the document are 4.7.34, 4.8.29, 4.9.30, 5.0.26, 5.1.23, 5.2.25, 5.3.22, 5.4.20, 5.5.19, 5.6.18, 5.7.16, 5.8.14, 5.9.14, 6.0.13, 6.1.11, 6.2.10, 6.3.9, 6.4.9, 6.5.9, 6.6.6, 6.7.6, 6.8.7, 6.9.6, And 7.0.3.

Note


The reference material explains that this vulnerability could lead to PHP code execution.