Threat Intelligence

Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now

The Hacker News · 7 Aug 2026
Key Takeaway If your business website runs on WordPress, update it to the latest version immediately and be cautious about clicking unfamiliar links while logged in as an administrator.

WordPress has released a fix for a serious security vulnerability found in its login screen. The flaw, tracked as CVE-2026-64638 and rated 8.9 out of 10 in severity, is a type of attack called cross-site scripting (XSS) that doesn't require a hacker to log in first — making it especially dangerous.

Security researchers at pwn.ai showed that this bug can be combined with other techniques to achieve full code execution on a website's server. In practice, this means that if a site administrator is logged in and lured into visiting a page controlled by an attacker, the attacker could potentially take complete control of the WordPress site, steal data, deface the website, or use it to launch further attacks.

Because the flaw affects every version of WordPress, this issue is relevant to almost any business running a WordPress-powered website — including many small businesses using it for e-commerce, blogs, or company pages. WordPress has already released a patch, so the priority now is making sure your site is updated as soon as possible.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.