hacker-news · Crawled Aug 7, 2026

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

Read original article ↗

AI Summary

A pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress, tracked as CVE-2026-64638, affects all versions and can be exploited without authentication. The XSS flaw exists in the login screen, where a malicious username can bypass sanitization and execute JavaScript on the failed-login error page. This XSS can be chained with the SOME technique to achieve PHP code execution on the server when an administrator interacts with an attacker-controlled page, enabling actions such as plugin installation or arbitrary ZIP upload without requiring the plugin to be activated.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.