WordPress Security Update Advisory (CVE-2026-64638)

WordPress Security Update Advisory (CVE-2026-64638)

Overview A security update has been released to address a vulnerability in WordPress. This vulnerability, identified as CVE-2026-64638, is a pre-authentication reflected cross-site scripting (XSS) vulnerability—a type of vulnerability that tricks users into executing malicious scripts—occurring on the WordPress login screen. Affected Versions The affected WordPress versions are as follows: