CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Companies

pwn.ai Discovers Critical WordPress XSS Chain

August 7, 2026

pwn.ai, a security research firm, discovered and responsibly disclosed CVE-2026-64638, a pre-authentication XSS vulnerability in WordPress that can lead to PHP code execution. The firm demonstrated the attack chain, named XSS2Shell, using an autonomous system and open-source models, and provided technical details to WordPress and The Hacker News.