Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress XSS Flaw Patched: Urgent Update Advised

Critical WordPress XSS Flaw Patched: Urgent Update Advised

Posted on August 7, 2026 By CWS

WordPress has recently addressed a significant pre-authentication reflected cross-site scripting (XSS) vulnerability affecting its login screen, a flaw present in all versions of the platform. The vulnerability, identified as CVE-2026-64638 with a CVSS score of 8.9, was demonstrated by pwn.ai to potentially lead to PHP code execution when an administrator interacts with a page controlled by an attacker.

Understanding the Vulnerability

This high-severity vulnerability requires no authentication from the attacker, allowing a crafted username to trigger JavaScript execution on the failed-login error page. The flaw, as described by pwn.ai to The Hacker News, can be exploited without any special privileges or configurations, affecting default WordPress installations.

The vulnerability’s exploitation path involves an administrator already logged in and interacting with an attacker-managed page, which could be as simple as a single click. This interaction could then be manipulated to install plugins or upload random ZIP files, paving the way for code execution.

WordPress’s Response and Recommendations

On August 6, WordPress released a patch for this issue in version 7.0.3, with updates backported to version 4.7. Users are strongly advised to update their systems immediately to mitigate the risk. Sites with automatic updates enabled will receive the patch automatically, but older versions remain vulnerable beyond the current backport range.

The vulnerability, coined XSS2Shell by pwn.ai, was discovered using automated systems based on Paulos Yibelo’s 2022 Same Origin Method Execution (SOME) research. WordPress, however, emphasizes that successful exploitation requires additional conditions such as social engineering and explicit user interaction.

Technical Details and Implications

The flaw results from improper handling of usernames during failed login attempts, passing through functions like sanitize_user() and wp_strip_all_tags(). These functions fail to filter out certain malicious inputs, allowing attacker-controlled elements on the failed-login page to interact with WordPress’s user-profile.js script.

The potential for PHP code execution poses severe risks, such as exposure of database credentials, unauthorized administrator creation, and execution of operating-system commands. Researchers warn that standard WordPress hardening measures may not fully protect against this XSS vulnerability, making the security update crucial.

In conclusion, WordPress’s swift action in patching this vulnerability highlights the importance of maintaining up-to-date security measures. Users are urged to apply the latest updates to safeguard their sites against potential threats.

The Hacker News Tags:cross-site scripting, CVE-2026-64638, Cybersecurity, PHP code execution, pwn.ai, reflected XSS, security advisory, vulnerability patch, web security, website security, WordPress 7.0.3, WordPress login, WordPress security, WordPress update, XSS flaw

Post navigation

Previous Post: Patchwork’s Espionage via Fake PDFs and Chat Apps
Next Post: Critical Linux Flaw Allows KVM Escape with Root Access

Related Posts

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials The Hacker News
Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
Malicious Vite npm Packages Exploit Blockchain for Cyberattack Malicious Vite npm Packages Exploit Blockchain for Cyberattack The Hacker News
Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack The Hacker News
Trellix Reports Source Code Breach Incident Trellix Reports Source Code Breach Incident The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark