• Sources: primary, analysis, discussion
  • Summary: WordPress 7.0.3 fixes CVE-2026-64638. What is reachable without an account on a default install is JavaScript execution in the WordPress origin. pwn.ai's chain reaches PHP execution only in its steps 1 to 5, which require a logged-in administrator to visit an attacker-hosted page, where the injected callback clicks the Application Password approval button inside that authenticated session. pwn.ai words the result as working against a logged-in administrator towards full remote code execution, and states the chain was discovered entirely autonomously by its multi-agent workflow using open source models over about four days. pwn.ai gives the affected range as every WordPress version under active maintenance before 7.0.3. The release fixes eleven further issues and is being backported to every branch back through 4.7. A full proof of concept has been public since 2026-08-07.
  • Why it matters: Unauthenticated script execution in the site origin plus public exploit code, with a documented escalation to PHP execution the moment an administrator opens an attacker page, moves patching from routine to immediate for every self-hosted site.
  • Follow-up: Track backport coverage across the older branches and observed exploitation in the wild.

send feedback on this story