WordPress security advisory (AV26-792)

Serial Number: AV26-792
Date: August 10, 2026

As of August 7, 2026, WordPress is affected by a vulnerability in the following product:

  • WordPress
    • prior to 7.0.3

Open-source reporting indicates that CVE-2026-64638 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Date modified: