{"id":12034,"date":"2026-08-07T14:49:04","date_gmt":"2026-08-07T20:49:04","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/"},"modified":"2026-09-29T15:59:48","modified_gmt":"2026-09-29T21:59:48","slug":"alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/","title":{"rendered":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected Product(s):<\/h2>\n\n<p class=\"wp-block-paragraph\"><br \/>WordPress Core \u2014 Content Management System (CMS)<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected Versions<\/strong><\/td><td><strong>Fixed Version<\/strong><\/td><\/tr><tr><td><strong>WordPress<\/strong><\/td><td>All versions (from 4.7 onwards)<\/td><td>7.0.3<\/td><\/tr><tr><td><strong>WordPress<\/strong><\/td><td>6.9.x branch<\/td><td>6.9.6<\/td><\/tr><tr><td><strong>WordPress<\/strong><\/td><td>4.7 \u2013 6.8.x branches<\/td><td>Backports applied<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">Versions prior to 4.7 are also affected but fall outside the project&#8217;s official backport range.<\/p>\n\n<h2 class=\"wp-block-heading\"><br \/>Description<\/h2>\n\n<p class=\"wp-block-paragraph\">A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers demonstrated that this flaw can be chained to achieve remote code execution (RCE) in PHP on the server when an authenticated administrator interacts with an attacker-controlled page, turning a browser-side bug into a full server compromise.<\/p>\n\n<p class=\"wp-block-paragraph\">The issue lies in how WordPress processes the username field during failed login attempts. The input passes through sanitize_user() and wp_strip_all_tags() (which internally uses strip_tags()), where a string with HTML tag structure that includes a space after the opening &lt; survives as plain text. Then, when passing through wp_kses_post(), the content is interpreted as allowed HTML, generating attacker-controlled DOM elements.<\/p>\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"995\" height=\"1024\" src=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/visualization-995x1024.png\" alt=\"\" class=\"wp-image-11661\" srcset=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/visualization-995x1024.png 995w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/visualization-291x300.png 291w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/visualization-768x791.png 768w, https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/08\/visualization.png 1360w\" sizes=\"(max-width: 995px) 100vw, 995px\" \/><\/figure>\n\n<p class=\"has-text-align-center wp-block-paragraph\"><strong>Figure 1 <\/strong>WordPress Exploitation Chain \u2014 CVE-2026-64638: From Pre-Authenticated XSS to Remote PHP Code Execution<\/p>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">Update immediately to the fixed versions:<\/p>\n\n<p class=\"wp-block-paragraph\">Current version Update to Method<br \/>WordPress 7.0.x 7.0.3 Dashboard \u2192 Updates \u2192 Update now<br \/>WordPress 6.9.x 6.9.6 Dashboard \u2192 Updates \u2192 Update now<br \/>WordPress 4.7 \u2013 6.8.x Backport applied Automatic or manual updates<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Official download:<\/strong><br \/>\u2022 https:\/\/wordpress.org\/download\/releases\/<\/p>\n\n<p class=\"wp-block-paragraph\">Sites with automatic background updates enabled should have already received the security update automatically. It is recommended to verify the installed version.<\/p>\n\n<p class=\"wp-block-paragraph\">To verify the installation you can:<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Via WP-CLI<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">wp core version<br \/>wp core update # update if necessary<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Version 7.0.3 release notes:<\/strong><br \/>\u2022 https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-3-release\/<\/p>\n\n<h2 class=\"wp-block-heading\">Mitigation<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Implement a WAF (Web Application Firewall) with XSS filtering rules on wp-login.php. Pantheon has already applied virtual patching at the network level on its platform.pantheon<\/li>\n\n\n\n<li>Restrict access to wp-login.php by IP through .htaccess or web server configuration (NGINX\/Apache), allowing only known administrator IPs.<\/li>\n\n\n\n<li>Disable the Application Passwords functionality if not used, in order to cut the RCE chain vector:<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">add_filter(&#8216;wp_is_application_passwords_available&#8217;, &#8216;__return_false&#8217;)<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Monitor access logs for requests to wp-login.php with usernames containing characters such as  or similar.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Note: Researchers explicitly warned that standard WordPress hardening measures should not be considered complete mitigation for the underlying XSS. The only definitive solution is to update.<\/p>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>The Hacker News \u2014 CVE-2026-64638: https:\/\/thehackernews.com\/2026\/08\/new-wordpress-pre-auth-xss-could-lead.html<\/li>\n\n\n\n<li>WordPress 7.0.3 Release (official): https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-3-release\/<\/li>\n\n\n\n<li>WordPress 7.0.3 \u2014 Version documentation: https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/<\/li>\n\n\n\n<li>Security Arsenal \u2014 Technical analysis CVE-2026-64638: https:\/\/securityarsenal.com\/blog\/cve-2026-64638<\/li>\n\n\n\n<li>Pantheon \u2014 Platform mitigations: https:\/\/docs.pantheon.io\/release-notes\/2026\/08\/wordpress-7-0-3<\/li>\n\n\n\n<li>GitHub Advisory:  https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-52p2-r8wf-jcrf<\/li>\n<\/ul>\n","protected":false},"featured_media":11614,"template":"","class_list":["post-12034","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project&#039;s official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project&#039;s official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-07T20:49:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T21:59:48+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project&#039;s official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#listItem\",\"name\":\"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/\",\"name\":\"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab\",\"description\":\"Affected Product(s): WordPress Core \\u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project's official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \\u2014 High. Researchers\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/WordPress-logotype-wmark.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#mainImage\",\"width\":1000,\"height\":1000},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\\\/#mainImage\"},\"datePublished\":\"2026-08-07T14:49:04-06:00\",\"dateModified\":\"2026-09-29T15:59:48-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab","description":"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project's official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#listItem","name":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#listItem","position":2,"name":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/","name":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab","description":"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project's official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#mainImage","width":1000,"height":1000},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/#mainImage"},"datePublished":"2026-08-07T14:49:04-06:00","dateModified":"2026-09-29T15:59:48-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab","og:description":"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project's official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","og:image:width":1000,"og:image:height":1000,"article:published_time":"2026-08-07T20:49:04+00:00","article:modified_time":"2026-09-29T21:59:48+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS - Beacon Lab","twitter:description":"Affected Product(s): WordPress Core \u2014 Content Management System (CMS) Versions prior to 4.7 are also affected but fall outside the project's official backport range. Description A critical pre-authenticated reflected XSS vulnerability has recently been reported on the login screen (wp-login.php) in WordPress CMS, tracked as CVE-2026-64638 with a CVSS score of 8.9 \u2014 High. Researchers","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png"},"aioseo_meta_data":{"post_id":"12034","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 21:59:48","updated":"2026-09-29 22:00:57","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-85 Pre-Authenticated XSS with Chain to PHP RCE in WordPress CMS","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-85-pre-authenticated-xss-with-chain-to-php-rce-in-wordpress-cms\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12034\/revisions"}],"predecessor-version":[{"id":12035,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12034\/revisions\/12035"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11614"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=12034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}