National Cyber Warfare Foundation (NCWF)

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP


0 user ratings
2026-08-10 10:21:56
milo
Blue Team (CND) , Attacks
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.