Security News New WordPress Pre-Auth XSS Could Lead to PHP Code Execution TheHackerNews Daniel Bender 07 Aug 2026 Share WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.