New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has patched CVE-2026-64638, a pre-authentication reflected XSS flaw in the login screen that affects every version of the CMS and can be chained into PHP code execution under the right conditions. Researchers at pwn.ai demonstrated the attack chain XSS2Shell, but WordPress says real-world escalation still depends on administrator interaction and social engineering. #WordPress #CVE-2026-64638 #pwn.ai #XSS2Shell

Keypoints

  • WordPress fixed CVE-2026-64638 in version 7.0.3.
  • The flaw is a pre-authentication reflected XSS in the login screen.
  • pwn.ai showed the issue can be chained into PHP code execution.
  • The attack can work on default WordPress installations.
  • WordPress urges immediate updating, with backports available for supported branches.

Read More: https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html