Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in WordPress

Multiple vulnerabilities, including CVE-2026-64638, affect WordPress versions prior to 7.0.3, enabling privilege escalation, data breaches, and Server-Side Request Forgery (SSRF).

The French National Cybersecurity Agency (ANSSI) has issued an advisory regarding multiple security vulnerabilities discovered in the WordPress content management system. These vulnerabilities affect all versions of WordPress prior to 7.0.3, which was released on August 6, 2026. The identified security flaws introduce significant risks to web server environments, including the potential for remote attackers to execute cross-site scripting (XSS), conduct Server-Side Request Forgery (SSRF), bypass security controls, and perform privilege escalation to gain unauthorized access to administrative functions. Organizations running self-hosted WordPress instances are advised to evaluate their exposure and apply the 7.0.3 patch to mitigate these vulnerabilities. Given the ubiquity of the WordPress platform, successful exploitation could facilitate widespread data exfiltration and server compromise.

Impact

Successful exploitation of these vulnerabilities could result in full administrative account takeover, unauthorized access to sensitive database content, and the ability to leverage the compromised server as a pivot point for internal network scanning or attacks against backend infrastructure via SSRF.

Recommendation

  • Upgrade all WordPress instances to version 7.0.3 or later immediately to address CVE-2026-64638.
  • Review web server access logs for anomalous requests to administrative endpoints, particularly those originating from unexpected IP addresses or containing suspicious URI patterns associated with SSRF or XSS.
  • Implement a Web Application Firewall (WAF) to filter common web exploitation patterns targeting CMS vulnerabilities.

Immediate actions

Patch all WordPress instances to 7.0.3

IT Operations 24h

Mitigations

Upgrade WordPress core

immediate IT Operations

CVE-2026-64638