As cited
Copy frozen at (site build).
vulnerabilities
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress patched a pre-authentication reflected cross-site scripting vulnerability affecting all versions of the content management system, tracked as CVE-2026-64638 with a CVSS score of 8.9. The flaw, present on the login screen, can potentially be chained to achieve PHP code execution on the affected server.
Why it matters: WordPress administrators and hosting providers must apply the patch immediately, as any unauthenticated attacker can exploit this vulnerability to execute arbitrary code without requiring valid credentials.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress patched a pre-authentication reflected cross-site scripting vulnerability affecting all versions of the content management system, tracked as CVE-2026-64638 with a CVSS score of 8.9. The flaw, present on the login screen, can potentially be chained to achieve PHP code execution on the affected server.
Why it matters: WordPress administrators and hosting providers must apply the patch immediately, as any unauthenticated attacker can exploit this vulnerability to execute arbitrary code without requiring valid credentials.
- Source published
- First seen by Cybersecurity Tracker