# WordPress patches critical XSS flaw CVE-2026-64638

Published: 2026-08-10 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/545a5bbe-6e9a-567b-83ce-0a5a9e1f6eb6/wordpress-patches-critical-xss-flaw-cve-2026-64638

> WordPress released a fix for a critical unauthenticated XSS bug that can lead to remote code execution if an admin clicks a malicious link.

CERT-FR's weekly bulletin highlights CVE-2026-64638, a critical vulnerability affecting all versions of WordPress, patched on August 6, 2026 with the release of WordPress 7.0.3. The flaw allows an unauthenticated attacker to perform indirect remote code injection (XSS), which can escalate to arbitrary remote code execution if a site administrator clicks a crafted malicious link.

Unlike CVE-2026-60137 and CVE-2026-63030 covered in a prior CERT-FR alert, this vulnerability impacts the entire WordPress codebase rather than specific plugins or versions, though exploitation requires administrator interaction, somewhat limiting the attack surface. Organizations running WordPress should apply the vendor patch promptly given the breadth of affected installations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-64638 (templated)

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-034

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/545a5bbe-6e9a-567b-83ce-0a5a9e1f6eb6/wordpress-patches-critical-xss-flaw-cve-2026-64638.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
