Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-64638: Debian Linux: Unauthenticated Remote Code Execution
CVE-2026-64638 · published 28 days ago
Summary
A security issue in Debian Linux's package manager allows an attacker to run malicious code on a system without being authenticated. This could happen if a user installs a compromised package. To protect your system, ensure you only install packages from trusted sources and keep your Debian Linux up to date with the latest security patches.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | wordpress | All versions |
| Debian:12 | debian | wordpress | All versions |
| Debian:13 | debian | wordpress | All versions |
| Debian:14 | debian | wordpress | All versions |
| – | wordpress | wordpress | All versions |
| Ubuntu:16.04:LTS | canonical | wordpress | All versions |
| Ubuntu:18.04:LTS | canonical | wordpress | All versions |
| Ubuntu:20.04:LTS | canonical | wordpress | All versions |
| Ubuntu:22.04:LTS | canonical | wordpress | All versions |
| Ubuntu:24.04:LTS | canonical | wordpress | All versions |
| Ubuntu:26.04:LTS | canonical | wordpress | All versions |
Original advisory text
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be ...
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
References
- https://security-tracker.debian.org/tracker/CVE-2026-64638 Vendor Advisory
- https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
- https://hackerone.com/reports/3877102
- https://ubuntu.com/security/CVE-2026-64638 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-64638 Third Party Advisory
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8w... Third Party Advisory
Severity
9.4
Critical
CVSS 4.0: 8.9 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS 31%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published7 Aug 2026
Updated2 Sep 2026
First seen7 Aug 2026
Sources
DEBIAN-CVE-2026-64638 · OSV
CVE-2026-64638 · NVD
CVE-2026-64638 · MITRE
UBUNTU-CVE-2026-64638 · OSV
Monitor software like this
Free during beta