New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
- ID
- 11935
- Status
- new
- Published
- 07 Aug 2026, 8:56 PM
- Fetched
- 08 Aug 2026, 6:08 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
Summary
No summary yet. It will appear after the daemon summarizes this item.