CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution
6 de Agosto de 2026, 22:53
WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now.
Related Posts:
- Metabase SQL Injection Zero-Day (CVSS 10) Exploited
- Multiple ClamAV Flaws Let Remote Attackers Cause DoS
- CryptoJS Randomness Vulnerability Drains Crypto Wallets
The post CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution appeared first on Daily CyberSecurity.