VORANT. Threat Intelligence Sign in Get the full feed

WordPress 7.0.3 Patches Multiple Vulnerabilities

elevated vulnerability

Multiple vulnerabilities in WordPress versions before 7.0.3 allow privilege escalation, data exposure, SSRF, XSS, and security bypass.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities affecting WordPress versions prior to 7.0.3. The flaws could allow an attacker to achieve privilege escalation, breach data confidentiality, perform server-side request forgery (SSRF), conduct indirect remote code injection via cross-site scripting (XSS), and bypass security policies.

One CVE, CVE-2026-64638, is referenced alongside the vendor's own security bulletin. No indication is given in the advisory of active exploitation in the wild; the recommended remediation is to apply the patches released by WordPress in the 7.0.3 update. Given WordPress's widespread deployment across websites of all sectors, unpatched instances remain exposed to these issues until updated.

Mentioned in this report

Vulnerabilities CVE-2026-64638templated

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0979

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free