Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress XSS Flaw Patched: Urgent Update Advised

Critical WordPress XSS Flaw Patched: Urgent Update Advised

Posted on August 7, 2026 By CWS

WordPress has recently addressed a significant pre-authentication reflected cross-site scripting (XSS) vulnerability affecting its login screen, a flaw present in all versions of the platform. The vulnerability, identified as CVE-2026-64638 with a CVSS score of 8.9, was demonstrated by pwn.ai to potentially lead to PHP code execution when an administrator interacts with a page controlled by an attacker.

Understanding the Vulnerability

This high-severity vulnerability requires no authentication from the attacker, allowing a crafted username to trigger JavaScript execution on the failed-login error page. The flaw, as described by pwn.ai to The Hacker News, can be exploited without any special privileges or configurations, affecting default WordPress installations.

The vulnerability’s exploitation path involves an administrator already logged in and interacting with an attacker-managed page, which could be as simple as a single click. This interaction could then be manipulated to install plugins or upload random ZIP files, paving the way for code execution.

WordPress’s Response and Recommendations

On August 6, WordPress released a patch for this issue in version 7.0.3, with updates backported to version 4.7. Users are strongly advised to update their systems immediately to mitigate the risk. Sites with automatic updates enabled will receive the patch automatically, but older versions remain vulnerable beyond the current backport range.

The vulnerability, coined XSS2Shell by pwn.ai, was discovered using automated systems based on Paulos Yibelo’s 2022 Same Origin Method Execution (SOME) research. WordPress, however, emphasizes that successful exploitation requires additional conditions such as social engineering and explicit user interaction.

Technical Details and Implications

The flaw results from improper handling of usernames during failed login attempts, passing through functions like sanitize_user() and wp_strip_all_tags(). These functions fail to filter out certain malicious inputs, allowing attacker-controlled elements on the failed-login page to interact with WordPress’s user-profile.js script.

The potential for PHP code execution poses severe risks, such as exposure of database credentials, unauthorized administrator creation, and execution of operating-system commands. Researchers warn that standard WordPress hardening measures may not fully protect against this XSS vulnerability, making the security update crucial.

In conclusion, WordPress’s swift action in patching this vulnerability highlights the importance of maintaining up-to-date security measures. Users are urged to apply the latest updates to safeguard their sites against potential threats.

The Hacker News Tags:cross-site scripting, CVE-2026-64638, Cybersecurity, PHP code execution, pwn.ai, reflected XSS, security advisory, vulnerability patch, web security, website security, WordPress 7.0.3, WordPress login, WordPress security, WordPress update, XSS flaw

Post navigation

Previous Post: Patchwork’s Espionage via Fake PDFs and Chat Apps
Next Post: Critical Linux Flaw Allows KVM Escape with Root Access

Related Posts

CISA Warns of Active n8n Vulnerability Exploitation CISA Warns of Active n8n Vulnerability Exploitation The Hacker News
New Exploit Targets Patched vBulletin Code Flaw New Exploit Targets Patched vBulletin Code Flaw The Hacker News
Hidden Comment Flaw in Azure DevOps Risks AI Exploitation Hidden Comment Flaw in Azure DevOps Risks AI Exploitation The Hacker News
AI Hacking, Chrome Vulnerabilities, SonicWall Attacks AI Hacking, Chrome Vulnerabilities, SonicWall Attacks The Hacker News
Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files The Hacker News
FBI Alerts on Russian Hackers Targeting Signal Keys FBI Alerts on Russian Hackers Targeting Signal Keys The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Flaw Allows KVM Escape with Root Access
  • Critical WordPress XSS Flaw Patched: Urgent Update Advised
  • Patchwork’s Espionage via Fake PDFs and Chat Apps
  • Microsoft and Apple Launch Key Security Updates
  • Open Source Faces Challenges and Evolves

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Flaw Allows KVM Escape with Root Access
  • Critical WordPress XSS Flaw Patched: Urgent Update Advised
  • Patchwork’s Espionage via Fake PDFs and Chat Apps
  • Microsoft and Apple Launch Key Security Updates
  • Open Source Faces Challenges and Evolves

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark