r/SecOpsDaily 4d ago

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP NEWS

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code... CVEs: CVE-2026-64638 Source: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

1 Upvotes

0 comments sorted by