A critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all WordPress versions has been patched in WordPress 7.0.3 and backported to the 4.7 branch. Discovered by pwn.ai, the flaw allows attacker-controlled JavaScript execution on the login error page without authentication, which can escalate to PHP code execution on servers when an administrator interacts with a malicious page, enabling plugin uploads or API credential creation. WordPress site operators are urged to update immediately to mitigate risks including remote code execution, credential exposure, and persistent site compromise.
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

