Kryptovalutaticker:
sysadmin från Cyber Security News

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

Guru Baran
5 hours ago
4 Visningar
0 Kommentarer
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server. Because the flaw sits in code that has shipped with WordPress since version 4.7, it touched effectively every actively maintained installation of the world’s most popular content management system, which powers more than 43% of all websites on the internet, putting an estimated 500 million-plus sites at risk before a fix landed. The chain begins on the ordinary login page, wp-login.php. When a username that does not exist is submitted, WordPress builds an error message using a sanitization function called...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!