WordPress security patch release for CVE-2026-64638
Security Patch Release
Summary
Hide ▲
Show ▼
WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately and said sites with automatic background updates should receive the patch automatically. The patch closes a pre-auth reflected XSS issue in the login screen that can be chained into deeper compromise under additional conditions.
Related Happenings
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch Release
H score66
First: 18.07.2026 00:20
Last: 18.07.2026 00:20
Sources 1
About this happening:
WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installati...
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch ReleaseAbout this happening: WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installati...
Latest development: 21.07.2026 19:41
WordPress sites saw wp2shell probing at 23:29 UTC on July 17, followed 13 minutes later by a clear SQL injection attempt; Wiz also described attacks that mass-scanned vulnerable installations, abused plugin upload functionality, installed PHP webshells, and targeted wp-config through admin-ajax.php.
Gravity SMTP security patch release for CVE-2026-4020
Security Patch Release
H score16
First: 20.06.2026 12:56
Last: 20.06.2026 12:56
Sources 1
About this happening:
Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...
Gravity SMTP security patch release for CVE-2026-4020
Security Patch ReleaseAbout this happening: Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch Release
H score43
First: 06.06.2026 17:09
Last: 06.06.2026 17:09
Sources 1
About this happening:
The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch ReleaseAbout this happening: The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
Google security patch release for CVE-2026-10881
Security Patch Release
H score26
First: 06.06.2026 10:28
Last: 06.06.2026 10:28
Sources 1
About this happening:
Google shipped Chrome 149 with patches for 429 security bugs, including CVE-2026-10881 in ANGLE, creating a broad browser update for users on Linux, Windows, and...
Google security patch release for CVE-2026-10881
Security Patch ReleaseAbout this happening: Google shipped Chrome 149 with patches for 429 security bugs, including CVE-2026-10881 in ANGLE, creating a broad browser update for users on Linux, Windows, and...
Timeline
-
07.08.2026 15:56 1 articles · 4h ago
pwn.ai reports WordPress login-screen XSS to WordPress
Initial Disclosurepwn.ai reported the reproduced WordPress login-screen XSS chain to WordPress after using open-source models and a multi-agent workflow to discover and reproduce the flaw. The login-page bug can execute without an account or extra victim interaction once a crafted request is delivered.
Show sources
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP — thehackernews.com — 07.08.2026 15:56
-
07.08.2026 15:56 2 articles · 4h ago
WordPress ships 7.0.3 to fix CVE-2026-64638
Mitigation Patch UpdateWordPress shipped 7.0.3 on August 6 to fix CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS and can, under additional conditions, be chained into PHP code execution. Fixes were backported through the 4.7 branch, and WordPress urged operators to update immediately.
Show sources
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP — thehackernews.com — 07.08.2026 15:56
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP — thehackernews.com — 07.08.2026 15:56