Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now
WordPress has released a fix for a serious security vulnerability found in its login screen. The flaw, tracked as CVE-2026-64638 and rated 8.9 out of 10 in severity, is a type of attack called cross-site scripting (XSS) that doesn't require a hacker to log in first — making it especially dangerous.
Security researchers at pwn.ai showed that this bug can be combined with other techniques to achieve full code execution on a website's server. In practice, this means that if a site administrator is logged in and lured into visiting a page controlled by an attacker, the attacker could potentially take complete control of the WordPress site, steal data, deface the website, or use it to launch further attacks.
Because the flaw affects every version of WordPress, this issue is relevant to almost any business running a WordPress-powered website — including many small businesses using it for e-commerce, blogs, or company pages. WordPress has already released a patch, so the priority now is making sure your site is updated as soon as possible.