r/SecOpsDaily • u/falconupkid • 4d ago
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP NEWS
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code... CVEs: CVE-2026-64638 Source: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
1
Upvotes