[CIVN-2026-0408] Cross-Site Scripting (XSS) Vulnerability in WordPress

By Published On: August 12, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Cross-Site Scripting (XSS) Vulnerability in WordPress


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


WordPress versions prior to 7.0.3

Overview


A Cross-Site Scripting (XSS) vulnerability has been reported in WordPress, which could allow an attacker to execute arbitrary JavaScript on the targeted system.


Target Audience:

All end-user organizations and individuals using WordPress.


Risk Assessment:

High risk of unauthenticated XSS exploitation.


Impact Assessment:

Potential for remote code execution and/or compromise of system.


Description


WordPress is an open-source content management system (CMS) used to create, manage, and publish websites and web applications.


A Cross-Site Scripting (XSS) vulnerability exist in WordPress due to improper handling and sanitization of input on the login screen. An unauthenticated attacker could exploit this vulnerability to execute arbitrary JavaScript on the targeted system.


Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript and, under specific conditions, potentially execute PHP code, leading to further compromise of the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://wordpress.org/news/2026/08/wordpress-7-0-3-release/



Vendor Information


WordPress

https://wordpress.org/


References


 

https://wordpress.org/news/2026/08/wordpress-7-0-3-release/


CVE Name

CVE-2026-64638




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8gREACgkQ3jCgcSdc

ys/d0Q/+LsAngBC29JVLfxMSqb8fXYpvedW46sMlyAhwbHciGOaFAQUKxImzOVBr

/3TylQO8IBBEsjj00dvF2RLHo+A2alw91O80ZPKr1eDOntCdOSYpV3qxhDOfwQEq

MB2rG+pmG9A0U4Q67cuCl1NwEYvE+gU6W4nIvy89/QBm2C2CQOggor6GP187frys

aptw2LYA3/5rupGdJpk3/NvFcUUhXvKNO+I/oqnX04g8CeMl3CNkF3UUcnaVS7lf

mQN41teQWwASrcSkmtXt12ffBvz1TwWdt5ezRnRQ6QjFAuhPezpaG/7Vukucwquc

SAhNKGQfE/d03gLNLsMsSbgFkkKdXMOPXwSlfk1qimHcGFVOjLDXw4mbO8jVFsC7

kfa2VOHdIWEjgZg16DOdz/kEORBLd515kfwo1cU8c5gsZAC2c+9qao7aZ5dgDVQr

Cbzl7qWYsSMLjPUzcPI83100nuujiDu1zRw4g5ks3uRlnfwl4/B3tkkKIoCwjCFv

B65/hAVExyplbeVDpiCo1zqQFsRL19M2+w4RWCFM+BUp97flu8Rm9BMzSN2tgMeT

nJ3+MUvO70uJFV2vtE6E8/3GIAPzTRJ74JarqXhLMHjK+NOUgYLjL26XLTPXrpxx

/y8vG6TJa73xNRRpK7ZVR2+lJSO3Hof/KrDCxbl9ZbXq5z0u4YQ=

=+gh4

—–END PGP SIGNATURE—–

Share this article