# WordPress 7.0.3 Patches Multiple Vulnerabilities

Published: 2026-08-07 · Severity: elevated
Canonical: https://vorant.io/reports/0a906c6e-4d6f-506a-8be0-a353a5cd281c/wordpress-7-0-3-patches-multiple-vulnerabilities

> Multiple vulnerabilities in WordPress versions before 7.0.3 allow privilege escalation, data exposure, SSRF, XSS, and security bypass.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities affecting WordPress versions prior to 7.0.3. The flaws could allow an attacker to achieve privilege escalation, breach data confidentiality, perform server-side request forgery (SSRF), conduct indirect remote code injection via cross-site scripting (XSS), and bypass security policies.

One CVE, CVE-2026-64638, is referenced alongside the vendor's own security bulletin. No indication is given in the advisory of active exploitation in the wild; the recommended remediation is to apply the patches released by WordPress in the 7.0.3 update. Given WordPress's widespread deployment across websites of all sectors, unpatched instances remain exposed to these issues until updated.

## Mentioned in this report

- Vulnerabilities: CVE-2026-64638 (templated)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0979

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0a906c6e-4d6f-506a-8be0-a353a5cd281c/wordpress-7-0-3-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
