Login
← All news

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

The Hacker News Security Hosting WordPress

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai…

Read the full story on The Hacker News https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
Most WordPress sites are compromised through something ordinary: an unpatched plugin, an abandoned theme, an account without two-factor. If you would rather updates and backups simply happened, CrockyHost hosting does them for you.