highCVE-2026-64638

WordPress Login Screen - Pre-Auth Reflected XSS

WordPress login screen (wp-login.php) is vulnerable to pre-authentication reflected cross-site scripting (XSS). A specially crafted URL causes arbitrary JavaScript execution in a victim's browser context. Under conditions outside the attacker's control, this may be escalated to remote code execution via social engineering. All WordPress versions prior to 7.0.3 are affected; the fix has been backported to all branches back to 4.7. The advisory does not disclose the exact vulnerable parameter; this template probes common wp-login.php query parameters for unescaped HTML reflection as a best-effort black-box detection method.

Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.

No signup. Takes about a minute. We request pages your server already serves publicly — nothing is written, exploited or brute-forced.

What this check actually does

  • Fingerprints the host — server, technologies, certificate and response headers.
  • Runs the WordPress Login Screen - Pre-Auth Reflected XSS detection against it.
  • Runs a short pass for common misconfigurations, exposed files and TLS problems.
  • Cross-references the detected versions against published CVEs.

Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.

Tags

cvecve2026wordpressxssreflectedpre-authwp-login

References