08 August 2026
Reference: CVE-2026-64638
1. What is being reported?
Researchers discovered a vulnerability in WordPress login screens that allows attackers to inject harmful scripts without needing to log in. If someone using your site is persuaded to visit a malicious website and interact with it, hackers could potentially take control of your WordPress site.
2. What this means in plain English
If your organisation uses WordPress for its website or blog, this flaw could let attackers compromise your site, potentially leading to data loss, website defacement, or further attacks. The risk depends on users being tricked into clicking harmful links, but the impact could be severe.
3. Could this affect a small business?
Any small business, charity, or club using WordPress could be affected, especially if they have users who might be targeted with phishing or social engineering attacks. Organisations not using WordPress are not affected by this issue.
4. What to do now
- Check if your WordPress site is running version 7.0.3 or later, or any version back to 4.7 with the latest security updates applied.
- If not updated, arrange for your WordPress installation to be updated immediately to the fixed version.
- Educate your staff and users to be cautious about clicking links from unknown or suspicious sources.
- Ask your IT provider to verify that your WordPress site is secure and monitor for any unusual activity.
5. Ask your IT provider
Can you confirm that our WordPress site is updated to the latest secure version that fixes the CVE-2026-64638 vulnerability?
6. Bottom line
Keep your WordPress site updated to prevent attackers from exploiting this serious vulnerability.
Information based on CISA KEV, NVD, and reputable security reporting.