NEWS: NITDA Warns WordPress Administrators of Critical Flaw Allowing Remote Code Execution

NITDA Warns WordPress Administrators of Critical Flaw Allowing Remote Code Execution



The National Information Technology Development Agency (NITDA), through its Computer Emergency Readiness and Response Team (NITDA-CERRT), has issued an urgent security advisory warning WordPress administrators about a high-severity core vulnerability tracked as CVE-2026-64638. 


Disclosed on August 6, 2026, the flaw—dubbed XSS2Shell—carries a CVSS rating of 8.9 and allows unauthenticated attackers to execute arbitrary PHP code and potentially take full control of affected web servers.


Recommended for You



The vulnerability originates as a pre-authentication reflected cross-site scripting (XSS) exposure on the default WordPress login screen (/wp-login.php). 


When a login attempt fails, sanitization parser differentials cause unvalidated markup to execute within the victim's browser context. 


If targeted against an active administrator session, the exploit can be chained using same-origin requests to issue unauthorized application passwords, upload malicious plugins, and achieve full remote code execution.


NITDA-CERRT has advised all website owners, hosting providers, and system administrators to update their installations immediately to WordPress 7.0.3 or apply backported security patches available for supported legacy branches (down to version 4.7). 


Additionally, organizations are urged to implement reputable Web Application Firewalls (WAF), limit administrative access, disable unused REST API features like JSONP, and maintain off-site backups to mitigate post-exploitation impacts.


"The pre-auth nature of the vulnerability means that attackers do not need valid credentials to exploit it, making it a significant threat to global and local web infrastructure." — NITDA-CERRT Security Advisory


#WordPressSecurity #CVE202664638 #NITDA #CyberSecurity #XSS2Shell #WordPressPatch #InfoSec


Latest News


Post a Comment

Previous Post Next Post