< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-07T18:26:23+05:30

WordPress Pre-Auth XSS Vulnerability (CVE-2026-64638) Enables PHP Code Execution – Urgent Patch Required

A pre-authentication reflected XSS vulnerability in WordPress login pages (CVE-2026-64638) enables remote code execution through chained attacks requiring admin interaction. The vulnerability was patched in WordPress 7.0.3, with urgent updates recommended for all affected versions.

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the

Read original article

*** END OF TRANSMISSION ***