WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
We have discovered 7,982,646 live websites that are affected by CVE-2026-64638.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 7,982,646 live websites (100% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1,384 versions ( 93% of all versions) |
| 2,514,620 websites | |
| 809,195 websites | |
| 468,296 websites | |
| 350,408 websites | |
| 344,215 websites | |
| 312,276 websites | |
| 255,328 websites | |
| 203,560 websites | |
| 203,058 websites | |
| 196,253 websites |
| .com | 3,445,220 websites |
| .de | 513,332 websites |
| .org | 409,162 websites |
| .net | 236,135 websites |
| .nl | 221,279 websites |
| .it | 212,922 websites |
| .co.uk | 196,593 websites |
| .ru | 171,101 websites |
| .pl | 153,011 websites |
| .fr | 148,965 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ** | ||
| ********.*********.com | ** | ||
| ***************.org | *** | ||
| ******.net | *** | ||
| ************.org | *** | ||
| *****************.com | *** | ||
| ****.br | *** | ||
| **********.com | *** | ||
| *********.de | *** | ||
| ****.io | *** |
FAQ