
WordPress XSS2Shell Flaw Lets Unauthenticated Attackers Gain Remote Code Execution
A newly disclosed CVE-2026-64638, a pre-authentication cross-site scripting flaw in WordPress Core’s login screen that can be chained into full server-side remote code execution, earning a CVSS score of 8.9 and the codename XSS2Shell. PwnAI Research found that inserting a space between an opening angle bracket and a tag name (e.g., < area) causes PHP’s […]
The post WordPress XSS2Shell Flaw Lets Unauthenticated Attackers Gain Remote Code Execution appeared first on Cyber Security News.