Cyber Resilience
← All news

WordPress security advisory (AV26-792)

Our takeCCCS confirms CVE-2026-64638 is under active exploitation in WordPress <7.0.3. Update now.
Sources (1)
What this means for you — Security leader:WordPress 7.0.3 patches CVE-2026-64638, confirmed under active exploitation. Update all self-hosted instances immediately and verify that auto-updates are enabled.
What this means for you — Lean IT orgs:If you run your own WordPress site, update it to version 7.0.3 or newer right away — this vulnerability is already being exploited in the wild.
What this means for you — MSP:Confirm that all client WordPress sites are updated to 7.0.3 or later; this CVE is under active exploitation and affects the majority of self-hosted instances.
What this means for you — Researcher:WordPress 7.0.3 patches CVE-2026-64638 under confirmed active exploitation per CCCS advisory AV26-792.