Back to all news
Security

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

The Hacker News·August 7, 2026·1 min read
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress fixed a pre-authentication reflected XSS flaw in its login screen affecting all versions. Tracked as CVE-2026-64638 with a CVSS score of 8.9, pwn.ai demonstrated chaining the flaw into PHP code execution when a logged-in administrator interacts with an attacker-controlled page.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store