VORANT. Threat Intelligence Sign in Get the full feed

WordPress patches critical XSS flaw CVE-2026-64638

elevated vulnerability technology

WordPress released a fix for a critical unauthenticated XSS bug that can lead to remote code execution if an admin clicks a malicious link.

CERT-FR's weekly bulletin highlights CVE-2026-64638, a critical vulnerability affecting all versions of WordPress, patched on August 6, 2026 with the release of WordPress 7.0.3. The flaw allows an unauthenticated attacker to perform indirect remote code injection (XSS), which can escalate to arbitrary remote code execution if a site administrator clicks a crafted malicious link.

Unlike CVE-2026-60137 and CVE-2026-63030 covered in a prior CERT-FR alert, this vulnerability impacts the entire WordPress codebase rather than specific plugins or versions, though exploitation requires administrator interaction, somewhat limiting the attack surface. Organizations running WordPress should apply the vendor patch promptly given the breadth of affected installations.

Mentioned in this report

Vulnerabilities CVE-2026-64638templated

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-034

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free