{"id":9307,"date":"2026-08-07T14:12:44","date_gmt":"2026-08-07T14:12:44","guid":{"rendered":"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/08\/07\/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap\/"},"modified":"2026-08-07T14:12:44","modified_gmt":"2026-08-07T14:12:44","slug":"new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap","status":"publish","type":"post","link":"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/08\/07\/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap\/","title":{"rendered":"New WordPress Pre-Auth XSS Could Lead to PHP Code Execution &#8211; Patch ASAP"},"content":{"rendered":"<p>\u200bWordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.<\/p>\n<p>Tracked as\u00a0CVE-2026-64638\u00a0(CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,\u00a0WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.<\/p>\n<p>Tracked as\u00a0CVE-2026-64638\u00a0(CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,\u00a0\u00a0The Hacker News<\/p>","protected":false},"excerpt":{"rendered":"<p>\u200bWordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as\u00a0CVE-2026-64638\u00a0(CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,\u00a0WordPress has fixed a&hellip;&nbsp;<a href=\"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/08\/07\/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap\/\" class=\"\" rel=\"bookmark\">Read More &raquo;<span class=\"screen-reader-text\">New WordPress Pre-Auth XSS Could Lead to PHP Code Execution &#8211; Patch ASAP<\/span><\/a><\/p>\n","protected":false},"author":0,"featured_media":9308,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts\/9307"}],"collection":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/comments?post=9307"}],"version-history":[{"count":0,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts\/9307\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/media\/9308"}],"wp:attachment":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/media?parent=9307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/categories?post=9307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/tags?post=9307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}