Skip to content

Known CVE

WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)

Pre-authentication reflected XSS in WordPress wp-login.php (CVE-2026-64638). The flaw exploits a parser differential between PHP strip_tags() and WordPress KSES. Tags with whitespace after < (e.g. "< area") survive strip_tags() but are normalized to valid HTML by KSES, leading to attacker-controlled DOM elements that trigger automatic JavaScript execution via user-profile.js. No user interaction required. Affects all WordPress versions < 7.0.3.

CVE-2026-64638

High2026CVSS 8.9CWE-79

cve2026 · wordpress · xss · rce · pwnai

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website