hacker-news · Crawled Aug 7, 2026
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Read original article ↗AI Summary
A pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress, tracked as CVE-2026-64638, affects all versions and can be exploited without authentication. The XSS flaw exists in the login screen, where a malicious username can bypass sanitization and execute JavaScript on the failed-login error page. This XSS can be chained with the SOME technique to achieve PHP code execution on the server when an administrator interacts with an attacker-controlled page, enabling actions such as plugin installation or arbitrary ZIP upload without requiring the plugin to be activated.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.