All findings

CVE-2026-64638 high

pwn.ai autonomously chains WordPress XSS into code execution

pwn.ai reports an autonomous open-model workflow that found and chained CVE-2026-64638 from pre-authentication reflected XSS into conditional RCE.

Bug class
Pre-authentication reflected XSS chained into conditional remote code execution
Affected codebase
WordPress core
Credited system
pwn.ai
Disclosed
August 7, 2026
Attribution
Self-reported attribution
Severity
high
Source status: pwn.ai publishes the autonomous discovery and exploitation workflow. WordPress' upstream advisory independently confirms the vulnerability, credits the pwn.ai team, and documents the 7.0.3 fix. The upstream credit names the team rather than the AI system.

Summary

The report begins with reflected XSS reachable before authentication and chains it through WordPress behavior into code execution under qualifying conditions. pwn.ai says its agents used open models and autonomously navigated the exploitation chain; WordPress accepted and fixed the issue in 7.0.3.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.