WordPress Patches Critical Pre-Authentication XSS Vulnerability (CVE-2026-64638)

WordPress has released a fix for a high-severity pre-authentication reflected cross-site scripting (XSS) flaw (CVE-2026-64638) found in its login screen, affecting all versions of the content management system. Researchers demonstrated how this vulnerability could be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page, posing a significant risk to WordPress installations.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai