WordPress XSS Vulnerability (CVE-2026-64638)
[ 6 August 2026 at 5:00pmET/2100UTC ] We are writing to inform you of a major WordPress vulnerability impacting versions 4.7 and above. Update your WordPress site to apply the security patch.
What happened?
- Versions of WordPress 4.7 and above are impacted by a cross-site scripting vulnerability
- The vulnerability has the potential to lead to PHP code execution by an attacker
- WordPress has released v7.0.3 to address this and is backporting security fixes to older versions
Current Status
- Patches are being rolled out across all cPanel accounts on Shared Hosting, DoOO, and Managed Hosting, as well as all standalone WordPress and WordPress Multisite setups on Managed Hosting.
Next Steps
- ACTION REQUIRED: Update WordPress to patched versions if the patch has not yet been applied to your site. Patches must be applied by users themselves on self-managed WordPress installations (such as those on Reclaim Cloud).
- For v7.0x, update to v7.0.3 (https://wordpress.org/news/2026/08/wordpress-7-0-3-release/)
- For v6.9x, update to v6.9.6 (https://wordpress.org/documentation/wordpress-version/version-6-9-6/)
- For v6.8x, update to v6.8.7 (https://wordpress.org/documentation/wordpress-version/version-6-8-7/)
- For older versions, either upgrade to v7.0.3 or apply the latest minor update available
Contact our Support Team
If you have any further questions or need assistance, please contact our support team.