Consumer Technology
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP - The Hacker News

What the report says
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
Loading debate for this article…
Other publishers covering this story
No additional verified coverage is currently clustered with this report.

MUMSA Daawa Show Calls on Parents to Reclaim Role in Child Upbringing Amid Digital DistractionsNile Post
Free internet access excites traders in Oyam marketThe Observer
LG officially denies reports that its smart TVs are secretly recording users - MashableMashable
Nintendo Customer Appreciation sale: Best deals you can still grab - MashableMashable
Professor Layton studio Level-5's CEO admits using AI to make its digital showcase "more spectacular" - Eurogamer.netEurogamer.net
Diablo 4 Annual Expansions Are Done As Blizzard Focuses On Seasonal Stories Leading Up To Diablo 5 - KotakuKotaku