WordPress has released 7.0.3 as a security update to fix multiple vulnerabilities, led by a high-severity pre-authentication reflected XSS flaw in the login screen tracked as CVE-2026-64638 and GHSA-52p2-r8wf-jcrf. The issue affects all WordPress versions and is being backported through the supported 4.7 security branch, while 7.1 RC2 also includes the fixes. WordPress said site owners should update immediately; versions older than 4.7 remain affected and are outside the current backport range.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On August 10, the Canadian Centre for Cyber Security published advisory AV26-792 warning that WordPress versions prior to 7.0.3 are affected by CVE-2026-64638. The advisory said open-source reporting indicated the vulnerability was being exploited in the wild as of August 7 and urged administrators to review WordPress guidance and apply updates.
A ProjectDiscovery Nuclei template was published for CVE-2026-64638 to detect the pre-authentication reflected XSS in WordPress Core versions before 7.0.3 via crafted POST requests to /wp-login.php. The accompanying material described a Docker-based proof of concept and reported successful detection against a local test instance, with the issue also said to have been validated against live targets.
As of August 7, WordPress said it had no evidence that CVE-2026-64638 had been exploited in the wild. The company also noted that the demonstrated RCE path depends on successful social engineering and conditions outside the attacker's control.
On August 6, WordPress released version 7.0.3 as a security update and urged site owners to update immediately. The release fixed multiple vulnerabilities, including the pre-auth login-screen XSS tracked as CVE-2026-64638, several stored XSS issues, a multisite privilege escalation bug, an SSRF flaw, and information disclosure weaknesses.
pwn.ai reported the full XSS2Shell exploitation chain for CVE-2026-64638 to WordPress with proof of exploitation, and WordPress acknowledged the report the same day. The acknowledgment preceded the 7.0.3 security release and later public disclosure.
pwn.ai reported that the login-screen XSS could be chained into server-side PHP code execution under additional conditions, including a logged-in administrator and social engineering. The researchers described multiple escalation paths, including plugin installation and arbitrary ZIP upload, using DOM injection, same-origin REST requests, and JSONP-based script execution.
WordPress said the security fixes in 7.0.3 were being backported where necessary to all supported branches eligible for security fixes, currently through version 4.7. Versions older than 4.7 remain affected and are outside the current backport range.
Researchers at pwn.ai discovered a pre-authentication reflected XSS flaw in the WordPress login screen and responsibly disclosed it to WordPress. The issue was later tracked as CVE-2026-64638.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourceboho.or.kr
Open sourcepwn.ai
Open sourcegithub.com
Open sourcegithub.com
Open sourcewordpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.