New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Summary
A critical pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress's login screen has been patched. The flaw, tracked as CVE-2026-64638, allows for PHP code execution under certain conditions and requires no prior attacker privileges. Users are urged to update immediately.
IFF Assessment
This vulnerability allows attackers to execute code on the server without authentication, posing a significant risk to websites running WordPress.
Severity
The high CVSS score is due to the vulnerability's pre-authentication nature, high impact (PHP code execution), and the wide reach of WordPress.
Defender Context
This vulnerability highlights the importance of keeping WordPress core and plugins updated promptly, as even pre-authentication flaws can have severe consequences like code execution. Defenders should monitor for any signs of exploitation and ensure their update strategy prioritizes critical vulnerabilities.