
WordPress Pre-Auth XSS (CVE-2026-64638) Can Escalate to RCE: Patch ASAP
August 7, 2026 — A high-severity WordPress pre auth XSS vulnerability has been fixed in WordPress core, impacting every currently supported version of the popular content management system prior to version 7.0.3. Tracked as CVE-2026-64638 with a CVSS score of 8.9, this flaw requires zero attacker privileges to trigger. Security researchers at pwn.ai discovered the ... Read more



















