WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution

WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pwn.ai discovered the flaw, which carries a CVSS score of 8.9 and affects every actively maintained WordPress branch, a codebase […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: