ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
WordPress login reflected XSS can escalate to PHP code execution (CVE-2026-64638)
Source headline: New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Threat level
Critical
Signal strength
85/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
WordPress has released a fix for a pre-auth reflected XSS issue in its login screen. The flaw can be triggered without any authenticated access. Under specific conditions, the vulnerability can be chained to achieve PHP code execution on the server. The problem is tracked as CVE-2026-64638 and carries a high CVSS score of 8.9. Users should update WordPress immediately to eliminate the risk.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Open original source