August 8, 2026
- WordPress patched XSS2Shell (CVE-2026-64638), a CVSS 8.9 pre-auth reflected XSS in the login screen that chains to PHP RCE. The XSS needs no account; researchers at pwn.ai — who say the bug was discovered autonomously — showed it chaining to code execution when a logged-in admin interacts with an attacker page (create API creds, gain REST access, upload a malicious plugin). The flaw affects every version of WordPress. The Hacker News · Vulnerabilities & Exploits
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold