New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

A critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all WordPress versions has been patched in WordPress 7.0.3 and backported to the 4.7 branch. Discovered by pwn.ai, the flaw allows attacker-controlled JavaScript execution on the login error page without authentication, which can escalate to PHP code execution on servers when an administrator interacts with a malicious page, enabling plugin uploads or API credential creation. WordPress site operators are urged to update immediately to mitigate risks including remote code execution, credential exposure, and persistent site compromise.

https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top