Detection of Multiple Vulnerabilities in WordPress Affecting Security
The National Cybersecurity Institute (INCIBE) issued an early warning on August 7, 2026, regarding vulnerabilities in WordPress. The alert highlights a high-severity vulnerability that could allow for reflected Cross-Site Scripting (XSS) with the potential for remote code execution.
Affected Versions by Vulnerabilities in WordPress
The affected versions are all those prior to the following updates released by WordPress:
- WordPress 7.0 prior to version 7.0.3
- WordPress 6.9 prior to version 6.9.6
- WordPress 6.8 prior to version 6.8.7
- WordPress 6.7 prior to version 6.7.6
- WordPress 6.6 prior to version 6.6.6
- WordPress 6.5 prior to version 6.5.9
- WordPress 6.4 prior to version 6.4.9
- WordPress 6.3 prior to version 6.3.9
- WordPress 6.2 prior to version 6.2.10
- WordPress 6.1 prior to version 6.1.11
- WordPress 6.0 prior to version 6.0.13
- WordPress 5.9 prior to version 5.9.14
- WordPress 5.8 prior to version 5.8.14
- WordPress 5.7 prior to version 5.7.16
- WordPress 5.6 prior to version 5.6.18
- WordPress 5.5 prior to version 5.5.19
- WordPress 5.4 prior to version 5.4.20
- WordPress 5.3 prior to version 5.3.22
- WordPress 5.2 prior to version 5.2.25
- WordPress 5.1 prior to version 5.1.23
- WordPress 5.0 prior to version 5.0.26
- WordPress 4.9 prior to version 4.9.30
- WordPress 4.8 prior to version 4.8.29
- WordPress 4.7 prior to version 4.7.34
Technical Details of Vulnerability CVE-2026-64638
The vulnerability CVE-2026-64638 is a reflected Cross-Site Scripting that occurs before authentication on the WordPress login screen. An attacker could host a malicious website and, through social engineering with victim interaction, exploit this vulnerability to achieve remote command execution.
Released Versions to Fix Vulnerabilities in WordPress
WordPress has released the following versions that address these vulnerabilities:
- Version 7.0.3 for the 7.0 branch
- Version 6.9.6 for the 6.9 branch
- Version 6.8.7 for the 6.8 branch
- Version 6.7.6 for the 6.7 branch
- Version 6.6.6 for the 6.6 branch
- Version 6.5.9 for the 6.5 branch
- Version 6.4.9 for the 6.4 branch
- Version 6.3.9 for the 6.3 branch
- Version 6.2.10 for the 6.2 branch
- Version 6.1.11 for the 6.1 branch
- Version 6.0.13 for the 6.0 branch
- Version 5.9.14 for the 5.9 branch
- Version 5.8.14 for the 5.8 branch
- Version 5.7.16 for the 5.7 branch
- Version 5.6.18 for the 5.6 branch
- Version 5.5.19 for the 5.5 branch
- Version 5.4.20 for the 5.4 branch
- Version 5.3.22 for the 5.3 branch
- Version 5.2.25 for the 5.2 branch
- Version 5.1.23 for the 5.1 branch
- Version 5.0.26 for the 5.0 branch
- Version 4.9.30 for the 4.9 branch
- Version 4.8.29 for the 4.8 branch
- Version 4.7.34 for the 4.7 branch
Alert Rating and Context
INCIBE has assigned this alert a level of importance 4, considered high. The alert does not provide details on active exploitation or ongoing attacks stemming from these vulnerabilities.
Original source: INCIBE - Multiple Vulnerabilities in WordPressPublished: 08/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
You can support the project or share this article in one click. At least this block does something useful.