WordPress XSS Vulnerability (CVE-2026-64638)

Share
WordPress XSS Vulnerability (CVE-2026-64638)
‼️
Impact: All WordPress sites running 4.7 or above

[ 6 August 2026 at 5:00pmET/2100UTC ] We are writing to inform you of a major WordPress vulnerability impacting versions 4.7 and above. Update your WordPress site to apply the security patch.

What happened?

  • Versions of WordPress 4.7 and above are impacted by a cross-site scripting vulnerability
  • The vulnerability has the potential to lead to PHP code execution by an attacker
  • WordPress has released v7.0.3 to address this and is backporting security fixes to older versions

Current Status

  • Patches are being rolled out across all cPanel accounts on Shared Hosting, DoOO, and Managed Hosting, as well as all standalone WordPress and WordPress Multisite setups on Managed Hosting.

Next Steps

Contact our Support Team

If you have any further questions or need assistance, please contact our support team.