Diamond Member ThaHaka 0 Posted Friday at 12:56 PM Diamond Member Share Posted Friday at 12:56 PM This is the hidden content, please Sign In or Sign Up WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai, This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/324597-h4ckn3wsnew-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.