AI Weekly Malaysia

Back to items Summaries

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

ID
11935
Status
new
Published
07 Aug 2026, 8:56 PM
Fetched
08 Aug 2026, 6:08 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Excerpt

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity

Summary

No summary yet. It will appear after the daemon summarizes this item.

Top