SECURITY·중요도 9·2026. 08. 07.·The Hacker News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
── KO ──────────────────
워드프레스에서 인증 전 XSS 취약점이 발견되어 패치가 필요합니다.
워드프레스는 모든 버전에서 발생하는 로그인 화면의 인증 전 반사형 크로스 사이트 스크립팅(XSS) 결함을 수정했습니다. pwn.ai는 이 결함이 공격자가 조종하는 페이지와 상호작용할 때, 로그인한 관리자에 의해 서버에서 PHP 코드 실행으로 이어질 수 있음을 보여주었습니다. 이 취약점은 CVE-2026-64638로 추적되며, CVSS 점수는 8.9입니다.
── EN ──────────────────
A pre-auth XSS vulnerability in WordPress requires an urgent patch.
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects all versions. This vulnerability can lead to PHP code execution on the server when a logged-in administrator interacts with a page controlled by an attacker, as demonstrated by pwn.ai. The flaw is tracked as CVE-2026-64638, with a CVSS score of 8.9.