← Back to CVE List
CVE-2026-64638Wordfence
Vulnerability Summary
WordPress Core is vulnerable to Reflected Cross-Site Scripting via the 'log' parameter in all versions up to, and including, 7.0.2 due to insufficient input sanitization and output escaping of the authentication error messages rendered on the login screen. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as visiting a specially crafted, attacker-controlled page that submits a request to the vulnerable site.
CVSS v3.1 Base Metrics — Score 6.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- WordPress 4.7.0 - 4.7.33
- WordPress 4.8.0 - 4.8.28
- WordPress 4.9.0 - 4.9.29
- WordPress 5.0.0 - 5.0.25
- WordPress 5.1.0 - 5.1.22
- WordPress 5.2.0 - 5.2.24
- WordPress 5.3.0 - 5.3.21
- WordPress 5.4.0 - 5.4.19
- WordPress 5.5.0 - 5.5.18
- WordPress 5.6.0 - 5.6.17
- WordPress 5.7.0 - 5.7.15
- WordPress 5.8.0 - 5.8.13
- WordPress 5.9.0 - 5.9.13
- WordPress 6.0.0 - 6.0.12
- WordPress 6.1.0 - 6.1.10
- WordPress 6.2.0 - 6.2.9
- WordPress 6.3.0 - 6.3.8
- WordPress 6.4.0 - 6.4.8
- WordPress 6.5.0 - 6.5.8
- WordPress 6.6.0 - 6.6.5
- WordPress 6.7.0 - 6.7.5
- WordPress 6.8.0 - 6.8.6
- WordPress 6.9.0 - 6.9.5
- WordPress 7.0.0 - 7.0.2
- WordPress 1