New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

144 Mastra npm Packages Compromised via Hijacked Contributor Account

144 Mastra npm Packages Compromised via Hijacked Contributor Account As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building

Relm4 makes developing beautiful cross-platform applications idiomatic

Relm4 makes developing beautiful cross-platform applications idiomatic Source: Hacker News

Apple Defeats Liability for Not Scanning iCloud for CSAM

Apple Defeats Liability for Not Scanning iCloud for CSAM Source: Hacker News