MEDIUMVulnerability
Global

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

·Source: The Hacker News

Updated:

Executive Summary

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

Analysis

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

Indicators of Compromise (1)

CVE (1)
CVE-2026-64638
Source Attribution

Originally published by The Hacker News on Aug 7, 2026.

Related Threats