New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

Summary

A critical pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress's login screen has been patched. The flaw, tracked as CVE-2026-64638, allows for PHP code execution under certain conditions and requires no prior attacker privileges. Users are urged to update immediately.

IFF Assessment

FOE

This vulnerability allows attackers to execute code on the server without authentication, posing a significant risk to websites running WordPress.

Severity

8.9 High

The high CVSS score is due to the vulnerability's pre-authentication nature, high impact (PHP code execution), and the wide reach of WordPress.

Defender Context

This vulnerability highlights the importance of keeping WordPress core and plugins updated promptly, as even pre-authentication flaws can have severe consequences like code execution. Defenders should monitor for any signs of exploitation and ensure their update strategy prioritizes critical vulnerabilities.

Read Full Story →