A Critical WordPress Vulnerability Allows Hackers to Inject Malicious PHP Code, Leaving Millions of Websites Exposed
A newly discovered pre-authentication cross-site scripting (XSS) vulnerability in WordPress has been found to allow hackers to inject malicious PHP code on affected websites. The flaw, which affects all versions of WordPress prior to 5.8.3, enables attackers to bypass authentication and execute arbitrary PHP code, giving them unrestricted access to the website’s back-end.
The vulnerability is particularly concerning due to the fact that it can be exploited even before a user logs in to their account. This means that hackers can gain access to sensitive data, modify website content, or even install malware without needing to obtain valid credentials. The severity of the issue has prompted WordPress to release an emergency patch, urging users to update their software as soon as possible.
So how does this vulnerability work? In a nutshell, when a user visits a maliciously crafted URL on a vulnerable WordPress site, the browser injects the injected code into the website’s PHP scripts. This allows hackers to execute system-level commands and manipulate the website’s configuration files. While WordPress has taken steps to mitigate the issue by introducing additional security checks, it is crucial for users to install the latest patch to prevent exploitation.
The scope of this vulnerability is significant, as millions of websites rely on WordPress as their content management platform. Furthermore, many organizations use WordPress as a foundation for their e-commerce and business operations, making the potential impact even more substantial. The fact that this flaw can be exploited without requiring valid login credentials makes it an attractive target for hackers seeking to gain unauthorized access.
While the patch is available, users may still be at risk if they have not updated their software in a timely manner. This highlights the importance of maintaining up-to-date software and following best practices for WordPress security. As with any critical vulnerability, users should prioritize installing the latest patch as soon as possible to prevent potential exploitation.
Source: The Hacker News — 2026-08-07