#4
The Hacker News
general
August 07, 2026 at 12:56 UTC
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
By [email protected] (The Hacker News)
AI Summary
WordPress has patched CVE-2026-64638 (CVSS 8.9), a pre-authentication reflected XSS flaw in the login screen affecting every version of the CMS that requires no attacker privileges. Under specific conditions the bug chains into server-side PHP code execution, making it critical for the hundreds of millions of WordPress deployments worldwide to apply the patch immediately.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →