pwn.ai, a security research firm, discovered and responsibly disclosed CVE-2026-64638, a pre-authentication XSS vulnerability in WordPress that can lead to PHP code execution. The firm demonstrated the attack chain, named XSS2Shell, using an autonomous system and open-source models, and provided technical details to WordPress and The Hacker News.