Security
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
The Hacker News·August 7, 2026·1 min read
WordPress fixed a pre-authentication reflected XSS flaw in its login screen affecting all versions. Tracked as CVE-2026-64638 with a CVSS score of 8.9, pwn.ai demonstrated chaining the flaw into PHP code execution when a logged-in administrator interacts with an attacker-controlled page.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
