Security notice: critical vulnerability in WordPress (CVE-2026-64638) – Update your site now!

Dear community!

INCIBE has published an advisory about a vulnerability of high severity (CVE-2026-64638) affecting multiple versions of WordPress. This flaw, a reflected Cross‑Site Scripting in the login screen, could allow an attacker, through social engineering, to achieve remote code execution on your site.

The affected versions are numerous, including all branches from 4.7 up to 7.0. The full list is in the INCIBE advisory.

The solution is simple but urgent :right_arrow: update WordPress to the patched version that corresponds to your branch. For example, if you’re using 6.9, you should update to 6.9.6. If you’re using 7.0, to 7.0.3, and so on.

Here is the full INCIBE advisory :backhand_index_pointing_right: Multiple vulnerabilities in WordPress

That’s it—take a look at your WordPress sites before the only "plugin" that gets updated is the attacker’s. Don’t be like that friend who always says "I’ll update tomorrow" and then does it when it’s already too late! :wink:

Regards, fellow members!
Sergio Turpín

Thank you very much @sturpin