# WordPress Pre-Auth XSS Flaw Could Enable PHP Code Execution – Patch Now

A newly disclosed cross-site scripting vulnerability in WordPress can be exploited without authentication, potentially allowing attackers to execute arbitrary PHP code. This could lead to full site compromise, so administrators are strongly advised to apply the available patch immediately.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html) — Fri, 07 Aug 2026 18:26:23 +0530