Tag

Cve 2026 64638

All articles tagged with #cve 2026 64638

WordPress XSS Chain Could Trigger Remote Code Execution, Patch Issued
technology17 days ago

WordPress XSS Chain Could Trigger Remote Code Execution, Patch Issued

Researchers disclosed a pre-auth, reflected XSS in WordPress login that can chain into PHP code execution on a site administrator's visit, via a multi-step path involving REST/JSONP calls and an attacker-controlled payload; the flaw, CVE-2026-64638, is rated 8.9/10 and affects all versions prior to the fix; WordPress released 7.0.3 on Aug 6 with backports to the 4.7 branch, and sites should update immediately; no known active exploits as of Aug 7.