WordPress security advisory (AV26-792)
Serial Number: AV26-792 Date: August 10, 2026 As of August 7, 2026, WordPress is affected by a vulnerability in the following product: WordPress prior to 7.0.3 Open-source reporting indicates that CVE-2026-64638 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WordPress 7.0.3 release – WordPress News
CSIRTS triage
- What
- WordPress contains a vulnerability (CVE-2026-64638) that is being actively exploited in the wild.
- Who is affected
- WordPress installations running versions prior to 7.0.3.
- Urgency
- High; CVE-2026-64638 is being actively exploited in the wild, requiring immediate patching.
- Action
- Upgrade WordPress to version 7.0.3 or later immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WordPress
Get an email when a new WordPress advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-792
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-646380.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64638 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] WordPress: Multiple vulnerabilitiescert-bund
- unknownDSA-6427-1 wordpress - security updatedebian
- unknownCVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a s…nvd
- unknownMultiple vulnerabilities in WordPress (August 07, 2026)cert-fr-avis
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24