XSS2Shell Turns a Failed WordPress Login Into Remote Code Execution on 500 Million Sites
A vulnerability chain in WordPress Core, dubbed XSS2Shell, lets an unauthenticated attacker turn a single failed login attempt into full PHP remote code execution. The 7.0.3 patch landed August 6, 2026 — 43% of the web needs to apply it now.