ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

WordPress login reflected XSS can escalate to PHP code execution (CVE-2026-64638)

Source headline: New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

WordPress has released a fix for a pre-auth reflected XSS issue in its login screen. The flaw can be triggered without any authenticated access. Under specific conditions, the vulnerability can be chained to achieve PHP code execution on the server. The problem is tracked as CVE-2026-64638 and carries a high CVSS score of 8.9. Users should update WordPress immediately to eliminate the risk.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#rce #wordpress #patch #preauth #xss #cve-2026-64638
Original reporting The Hacker News New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
Open original source