WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an a...
**Source : The Hacker News | 7 août 2026**
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.
Tracked as CVE-2026-64638 (CVSS score: 8.9), the
👉 **Lire l'article complet sur The Hacker News :** [https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html](https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html)
Commentaires (0)
Laisser un commentaire
Aucun commentaire pour le moment. Soyez le premier à commenter !