New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU Source: Hacker News

Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too

Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 20.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 4.223.113.180 — 241 requests (recent log) 89.167.35.212 — 218 requests (recent log) 216.73.216.43 — 108 requests (recent