WordPress High · CVSS 8.9 CVE-2026-64638 August 6, 2026

WordPress Core 6.4-7.0.2 (i starsze gałęzie): security vulnerability

WordPress Core 6.4-7.0.2 (i starsze gałęzie)

Security vulnerability in the WordPress Core 6.4-7.0.2 (i starsze gałęzie) component. Threat level: High (CVSS 8.9).

Worried this flaw is on your site? Check it for free in under a minute, or have us fix and secure it right away.

Who is affected

This vulnerability affects: WordPress Core 6.4-7.0.2 (i starsze gałęzie). If you use this component on your site, check the version and update it as soon as possible.

How dangerous

Rating: High, CVSS 8.9 out of 10. It is worth acting before the flaw is exploited.

What to do

  • Update the vulnerable component (WordPress Core 6.4-7.0.2 (i starsze gałęzie)) to the latest version.
  • If a patch is not out yet, temporarily disable the vulnerable element.
  • Check whether the site has already been attacked: unusual files, new administrator accounts, redirects.
  • Make a backup before you start making changes.
Do not guess, check

Does this flaw affect your site?

We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.

Request a free audit →

Other current WordPress threats

MemberDash: security vulnerability CVE-2026-16310 · Critical HivePress Authentication: authentication bypass CVE-2026-18056 · High Frontend Admin by DynamiApps: authentication bypass CVE-2026-75816 · Critical SureCart WordPress: security vulnerability CVE-2026-18480 · High See the full list →