News
XSS2Shell: WordPress Pre-Auth RCE Starts in strip_tags()
WordPress 7.0.3 patches CVE-2026-64638, a pre-auth XSS to RCE chain that begins with a parser disagreement between PHP's strip_tags() and KSES.
Eric L. Barnes
WordPress 7.0.3 patches CVE-2026-64638, a pre-auth XSS to RCE chain that begins with a parser disagreement between PHP's strip_tags() and KSES.
Eric L. Barnes