daily cyber × ai intelligence

index

tagged

[CVE-2026-64638]

1 edition · 1 item

August 8, 2026

  • WordPress patched XSS2Shell (CVE-2026-64638), a CVSS 8.9 pre-auth reflected XSS in the login screen that chains to PHP RCE. The XSS needs no account; researchers at pwn.ai — who say the bug was discovered autonomously — showed it chaining to code execution when a logged-in admin interacts with an attacker page (create API creds, gain REST access, upload a malicious plugin). The flaw affects every version of WordPress. The Hacker News · Vulnerabilities & Exploits

in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold