Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress XSS Flaw Patched: Urgent Update Advised

Critical WordPress XSS Flaw Patched: Urgent Update Advised

Posted on August 7, 2026 By CWS

WordPress has recently addressed a significant pre-authentication reflected cross-site scripting (XSS) vulnerability affecting its login screen, a flaw present in all versions of the platform. The vulnerability, identified as CVE-2026-64638 with a CVSS score of 8.9, was demonstrated by pwn.ai to potentially lead to PHP code execution when an administrator interacts with a page controlled by an attacker.

Understanding the Vulnerability

This high-severity vulnerability requires no authentication from the attacker, allowing a crafted username to trigger JavaScript execution on the failed-login error page. The flaw, as described by pwn.ai to The Hacker News, can be exploited without any special privileges or configurations, affecting default WordPress installations.

The vulnerability’s exploitation path involves an administrator already logged in and interacting with an attacker-managed page, which could be as simple as a single click. This interaction could then be manipulated to install plugins or upload random ZIP files, paving the way for code execution.

WordPress’s Response and Recommendations

On August 6, WordPress released a patch for this issue in version 7.0.3, with updates backported to version 4.7. Users are strongly advised to update their systems immediately to mitigate the risk. Sites with automatic updates enabled will receive the patch automatically, but older versions remain vulnerable beyond the current backport range.

The vulnerability, coined XSS2Shell by pwn.ai, was discovered using automated systems based on Paulos Yibelo’s 2022 Same Origin Method Execution (SOME) research. WordPress, however, emphasizes that successful exploitation requires additional conditions such as social engineering and explicit user interaction.

Technical Details and Implications

The flaw results from improper handling of usernames during failed login attempts, passing through functions like sanitize_user() and wp_strip_all_tags(). These functions fail to filter out certain malicious inputs, allowing attacker-controlled elements on the failed-login page to interact with WordPress’s user-profile.js script.

The potential for PHP code execution poses severe risks, such as exposure of database credentials, unauthorized administrator creation, and execution of operating-system commands. Researchers warn that standard WordPress hardening measures may not fully protect against this XSS vulnerability, making the security update crucial.

In conclusion, WordPress’s swift action in patching this vulnerability highlights the importance of maintaining up-to-date security measures. Users are urged to apply the latest updates to safeguard their sites against potential threats.

The Hacker News Tags:cross-site scripting, CVE-2026-64638, Cybersecurity, PHP code execution, pwn.ai, reflected XSS, security advisory, vulnerability patch, web security, website security, WordPress 7.0.3, WordPress login, WordPress security, WordPress update, XSS flaw

Post navigation

Previous Post: Patchwork’s Espionage via Fake PDFs and Chat Apps
Next Post: Critical Linux Flaw Allows KVM Escape with Root Access

Related Posts

10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux 10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux The Hacker News
Agentic AI: Emerging Security Challenges Explained Agentic AI: Emerging Security Challenges Explained The Hacker News
New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations The Hacker News
Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games The Hacker News
Chainguard Reaches 1 Billion Build Manifests Milestone Chainguard Reaches 1 Billion Build Manifests Milestone The Hacker News
Linux KVM Bug Risks Host Security on Intel and AMD Linux KVM Bug Risks Host Security on Intel and AMD The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security
  • Ransomware Exploits Active Directory for Disruption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security
  • Ransomware Exploits Active Directory for Disruption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark