New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Overview
WordPress has addressed a serious vulnerability in its login screen that affects all versions of the platform. This flaw, known as CVE-2026-64638 and rated with a CVSS score of 8.9, allows for pre-authentication reflected cross-site scripting (XSS). Researchers from pwn.ai have demonstrated that this vulnerability could potentially be exploited to execute PHP code on the server, particularly if an administrator interacts with a malicious page. As this issue impacts every WordPress installation, users and website administrators are strongly encouraged to apply the patch immediately to secure their sites and prevent potential exploitation.
Key Takeaways
- Affected Systems: All versions of WordPress content management system
- Action Required: Update to the latest version of WordPress where the vulnerability is patched.
- Timeline: Newly disclosed
Original Article Summary
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the
Impact
All versions of WordPress content management system
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Update to the latest version of WordPress where the vulnerability is patched. Users should check for updates and apply them as soon as possible.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Patch, and 1 more.