New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has patched a critical pre-authentication XSS vulnerability (CVE-2026-64638, CVSS 8.9) affecting all versions, which can be chained into remote PHP code execution if an admin clicks a malicious link. Users are urged to update immediately.
WordPress has patched a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability, CVE-2026-64638 (CVSS 8.9), affecting all versions. The flaw exists in the login screen. Security firm pwn.ai demonstrated that when a logged-in administrator interacts with an attacker-controlled page, the XSS can be chained into remote PHP code execution on the server. Users are urged to apply the fix immediately.