HackerFeeds

CyberSecurity News

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

The Hacker News
· August 7, 2026

AI summary

A pre-authentication reflected cross-site scripting flaw has been discovered in the WordPress login screen, affecting all versions of the content management system. This vulnerability can potentially lead to PHP code execution on the server under certain conditions. The flaw is considered high-severity with a CVSS score of 8.9 and is tracked as CVE-2026-64638. It does not require any attacker privileges to exploit. WordPress has issued a fix for the vulnerability.

Read the full article at The Hacker Newsthehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.