TL;DR
WordPress 7.0.3 is out as a security release. This WordPress security update fixes about a dozen flaws. The most serious is CVE-2026-64638, a pre-auth cross-site scripting bug that can escalate to remote code execution. It scores 8.9. Update your sites right away.
Why it matters
WordPress powers a large share of the web. A pre-auth flaw needs no login to start. Therefore this WordPress security update reaches a huge base of sites.
How the attack works
The headline flaw is a reflected XSS bug on the login screen. It needs no prior authentication. Under certain conditions, an attacker can push it toward remote code execution.
That escalation is not automatic. Per the advisory, it “requires successful social engineering of and explicit interaction by the target victim.” A malicious third-party site sets the trap. This report withholds working exploit steps.
Other fixes
The release also patches several stored XSS bugs. Additional fixes cover a multisite privilege escalation, an SSRF issue, and information disclosure flaws.
Exploitation status
No public proof-of-concept or in-the-wild exploitation has been confirmed. Researchers reported the flaws responsibly before the release.
Affected versions
The flaws affect WordPress versions before 7.0.3. Fixes are being backported to older branches, currently through 4.7.
Patch and mitigation
Update to WordPress 7.0.3 immediately. Many sites auto-update for security releases. Still, confirm your version to be safe. See the official WordPress 7.0.3 release announcement for details.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.