Detection of Multiple Vulnerabilities in WordPress Affecting Security

Published:
Illustrative image about Detection of Multiple Vulnerabilities in WordPress Affecting Security

The National Cybersecurity Institute (INCIBE) issued an early warning on August 7, 2026, regarding vulnerabilities in WordPress. The alert highlights a high-severity vulnerability that could allow for reflected Cross-Site Scripting (XSS) with the potential for remote code execution.

Affected Versions by Vulnerabilities in WordPress

The affected versions are all those prior to the following updates released by WordPress:

  • WordPress 7.0 prior to version 7.0.3
  • WordPress 6.9 prior to version 6.9.6
  • WordPress 6.8 prior to version 6.8.7
  • WordPress 6.7 prior to version 6.7.6
  • WordPress 6.6 prior to version 6.6.6
  • WordPress 6.5 prior to version 6.5.9
  • WordPress 6.4 prior to version 6.4.9
  • WordPress 6.3 prior to version 6.3.9
  • WordPress 6.2 prior to version 6.2.10
  • WordPress 6.1 prior to version 6.1.11
  • WordPress 6.0 prior to version 6.0.13
  • WordPress 5.9 prior to version 5.9.14
  • WordPress 5.8 prior to version 5.8.14
  • WordPress 5.7 prior to version 5.7.16
  • WordPress 5.6 prior to version 5.6.18
  • WordPress 5.5 prior to version 5.5.19
  • WordPress 5.4 prior to version 5.4.20
  • WordPress 5.3 prior to version 5.3.22
  • WordPress 5.2 prior to version 5.2.25
  • WordPress 5.1 prior to version 5.1.23
  • WordPress 5.0 prior to version 5.0.26
  • WordPress 4.9 prior to version 4.9.30
  • WordPress 4.8 prior to version 4.8.29
  • WordPress 4.7 prior to version 4.7.34

Technical Details of Vulnerability CVE-2026-64638

Additional image about Detection of Multiple Vulnerabilities in WordPress Affecting Security

The vulnerability CVE-2026-64638 is a reflected Cross-Site Scripting that occurs before authentication on the WordPress login screen. An attacker could host a malicious website and, through social engineering with victim interaction, exploit this vulnerability to achieve remote command execution.

Released Versions to Fix Vulnerabilities in WordPress

WordPress has released the following versions that address these vulnerabilities:

  • Version 7.0.3 for the 7.0 branch
  • Version 6.9.6 for the 6.9 branch
  • Version 6.8.7 for the 6.8 branch
  • Version 6.7.6 for the 6.7 branch
  • Version 6.6.6 for the 6.6 branch
  • Version 6.5.9 for the 6.5 branch
  • Version 6.4.9 for the 6.4 branch
  • Version 6.3.9 for the 6.3 branch
  • Version 6.2.10 for the 6.2 branch
  • Version 6.1.11 for the 6.1 branch
  • Version 6.0.13 for the 6.0 branch
  • Version 5.9.14 for the 5.9 branch
  • Version 5.8.14 for the 5.8 branch
  • Version 5.7.16 for the 5.7 branch
  • Version 5.6.18 for the 5.6 branch
  • Version 5.5.19 for the 5.5 branch
  • Version 5.4.20 for the 5.4 branch
  • Version 5.3.22 for the 5.3 branch
  • Version 5.2.25 for the 5.2 branch
  • Version 5.1.23 for the 5.1 branch
  • Version 5.0.26 for the 5.0 branch
  • Version 4.9.30 for the 4.9 branch
  • Version 4.8.29 for the 4.8 branch
  • Version 4.7.34 for the 4.7 branch

Alert Rating and Context

INCIBE has assigned this alert a level of importance 4, considered high. The alert does not provide details on active exploitation or ongoing attacks stemming from these vulnerabilities.

Original source: INCIBE - Multiple Vulnerabilities in WordPress
Reviewed by
Published: 08/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.