News

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-08-07 16:48:22 UTC

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a user…

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite … [+5559 chars]