Liquid Web Status · History · Incident #6291
ACTIVE INCIDENTSecurity Advisory: WordPress XSS2Shell Vulnerability (CVE-2026-64638)
Minor · Started Aug 8, 2026 · 9:24 AM
$HTTP_PROTOCOL = (isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1)) || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https') ? 'https://' : 'http://'; $SITE_URL = $HTTP_PROTOCOL . $_SERVER['SERVER_NAME'] . '/'; ?>
Liquid Web Status · History · Incident #6291
ACTIVE INCIDENTMinor · Started Aug 8, 2026 · 9:24 AM
Duration
Ongoing
Severity
Minor
Detection lead
—
User reports
—
Summary
A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution. Impacted versions Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7 Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please contact our Support team.
Started
Aug 8, 2026 · 9:24 AM
Status
Investigating
Duration
Ongoing
Severity
None
Event timeline
Investigating
Aug 8 · 9:24 AM Liquid WebA high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution. Impacted versions Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7 Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please contact our Support team.
Pattern
Pulsetic catches degradations minutes before vendors acknowledge them.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026. Pulsetic® is a registered trademark.