
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server. Because the flaw sits in code that has shipped with WordPress since version 4.7, it touched effectively every actively maintained installation of the world’s most popular […]
The post WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution appeared first on Cyber Security News.