New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Growing Up The Hard Way

Next Post

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Related Posts
Total
0
Share