Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Urgent WordPress Security Flaw Could Let Hackers Run Code

A serious security flaw has been found in all versions of WordPress that could allow hackers to run malicious code on your website if a user is tricked into interacting with a harmful webpage. This vulnerability has been fixed in the latest WordPress updates.

08 August 2026

Reference: CVE-2026-64638

1. What is being reported?

Researchers discovered a vulnerability in WordPress login screens that allows attackers to inject harmful scripts without needing to log in. If someone using your site is persuaded to visit a malicious website and interact with it, hackers could potentially take control of your WordPress site.

2. What this means in plain English

If your organisation uses WordPress for its website or blog, this flaw could let attackers compromise your site, potentially leading to data loss, website defacement, or further attacks. The risk depends on users being tricked into clicking harmful links, but the impact could be severe.

3. Could this affect a small business?

Any small business, charity, or club using WordPress could be affected, especially if they have users who might be targeted with phishing or social engineering attacks. Organisations not using WordPress are not affected by this issue.

4. What to do now

  • Check if your WordPress site is running version 7.0.3 or later, or any version back to 4.7 with the latest security updates applied.
  • If not updated, arrange for your WordPress installation to be updated immediately to the fixed version.
  • Educate your staff and users to be cautious about clicking links from unknown or suspicious sources.
  • Ask your IT provider to verify that your WordPress site is secure and monitor for any unusual activity.

5. Ask your IT provider

Can you confirm that our WordPress site is updated to the latest secure version that fixes the CVE-2026-64638 vulnerability?

6. Bottom line

Keep your WordPress site updated to prevent attackers from exploiting this serious vulnerability.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs