URL has been copied successfully!
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link