|
A simple stored XSS bug in WordPress, now tracked as CVE-2026-64638, was just chained into complete remote code execution. No login. No plugin. Just a comment box nobody thought twice about, and given how much of the web runs on WordPress, that's a problem for a lot of people.
|