tech ๐จ WordPress login flaw lets hackers run code remotely
A critical vulnerability chain, CVE-2026-64638 (XSS2Shell), allows an attacker to achieve remote code execution on a server. This issue was found in WordPress Core, affecting over 500 million sites globally. The exploit begins via a failed login attempt on wp-login.php, leveraging parser disagreements. This chain can escalate to full remote code execution if an admin interacts with a malicious page. WordPress released an emergency fix in version 7.0.3 on August 6, 2026. ๐ ๏ธ