News: Important WordPress Security Update
On August 6, 2026, a security vulnerability in WordPress Core was disclosed under CVE-2026-64638, also referred to as XSS2Shell.
The vulnerability affects the WordPress login screen and, under certain circumstances, can be exploited through a reflected XSS attack. If a logged-in WordPress administrator is successfully targeted, the vulnerability could ultimately allow PHP code to be executed within the affected website.
Due to the potential impact, we strongly recommend that WordPress users treat this security update with high priority.
Which WordPress installations are affected?
The vulnerability affects WordPress versions that are currently within the WordPress security backport range, from WordPress 4.7.0 through 7.0.2.
WordPress has released security updates addressing this vulnerability.
If you use WordPress, please verify that your installation has been updated to a version containing the security fix.
What should you do?
We recommend that you:
* update WordPress Core to the latest available secure version as soon as possible;
* check older or no longer actively used WordPress installations as well;
* update plugins and themes where possible;
* verify that both your website and WordPress administration area operate correctly after the update.
If automatic WordPress Core updates are enabled, the security update may already have been installed automatically. Nevertheless, we recommend checking the currently installed WordPress version.
Very old WordPress installations
WordPress installations older than version 4.7 fall outside the current WordPress security backport policy. Although the underlying vulnerability may also exist in older installations, separate security updates may not be provided for these versions.
If you are still using such an outdated WordPress version, we strongly recommend upgrading the website to a current and supported WordPress release.
No simple workaround
There is no simple workaround for this vulnerability, such as blocking a specific URL or WordPress REST API endpoint.
The recommended solution is to install the official WordPress Core security update.
Need assistance?
If you are unsure which WordPress version your website is using or would like assistance with the update, please feel free to contact us.
Vservs is happy to assist you in checking and keeping your website secure.
Vservs B.V.
Hosting & Server Solutions