Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
The Hacker News
4 days ago

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

By info@thehackernews.com (The Hacker News)

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.