Liquid Web Status · History · Incident #6291

RESOLVED

Security Advisory: WordPress XSS2Shell Vulnerability (CVE-2026-64638)

Minor · Started Aug 8, 2026 · 9:24 AM

  • Duration

    26d 28m

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

Security Advisory: WordPress XSS2Shell Vulnerability (CVE-2026-64638)

The WordPress security vulnerability CVE-2026-64638 has been addressed in the latest WordPress security releases. Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch. We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations. At this time, the incident has been resolved, and the related status page notification will be closed.


  • Started

    Aug 8, 2026 · 9:24 AM

  • Resolved

    Sep 3, 2026 · 9:53 AM

  • Duration

    26d 28m

  • Severity

    None

Event timeline

How this incident unfolded

  • Investigating

    Aug 8 · 9:24 AM Liquid Web

    A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution. Impacted versions Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7 Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please contact our Support team.

  • Resolved

    Sep 3 · 9:53 AM Liquid Web

    The WordPress security vulnerability CVE-2026-64638 has been addressed in the latest WordPress security releases. Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch. We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations. At this time, the incident has been resolved, and the related status page notification will be closed.

Get alerted before the next Liquid Web outage.

Pulsetic catches degradations minutes before vendors acknowledge them.