New WordPress Pre-Auth XSS Could Lead to PHP Code Execution
- Posted on August 7, 2026
- By The Hacker News
- 0 Views
- 1 min read
In brief
Generating AI summary…
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.