CVE-2026-64638: Pre-auth reflected XSS in WordPress, 8.9 rating 🔥
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
👉 Link: https://nt.ls/SjACB
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
Post #608
564

- 🔥 3
- ❤ 2