A newly discovered CVE-2026-64638, a pre-authentication cross-site scripting vulnerability in WordPress Core’s login screen that can be escalated to full server-side remote code execution This article explores attacker javascript unfiltered_html. . PwnAI Research revealed that inserting a space between an opening angle bracket and a tag name (e.g., ) causes PHP’s strip_tags() parser to treat the string as harmless text.

The XSS2Shell Flaw While WordPress's subsequent KSES sanitizer reinterprets the same string as legitimate HTML elements, it allows attackers to smuggle live, controlled ,

, and