WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pwn.ai discovered the flaw, which carries a CVSS score of 8.9 and affects every actively maintained WordPress branch, a codebase […] The post WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/critical-wordpress-vulnerability/
![]()

