
WordPress patches pre-auth XSS flaw that could be chained to code execution
WordPress has released security updates for a high-severity pre-authentication reflected cross-site scripting vulnerability tracked as CVE-2026-64638. The flaw affects the login page and can be triggered through a malicious link without the attacker first having an account. Researchers showed that, under specific conditions involving an administrator session, the XSS could be chained with WordPress functions to create credentials and ultimately execute PHP code. The fix is included in WordPress 7.0.3 and was backported to supported older branches.