vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability, tracked as CVE-2026-64638, can be exploited without requiring an account or additional interaction… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638