Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Nexcess

Security Advisory: WordPress XSS2Shell Vulnerability (CVE-2026-64638)

Resolved Minor
August 08, 2026 - Started about 1 month ago - Lasted 25 days
Official incident page

Incident Report

Summary AI Generated

A high-severity reflected XSS vulnerability (CVE-2026-64638) was identified in the WordPress login interface, affecting all WordPress versions from 4.7 through 7.0.2, with the potential under specific conditions to escalate to PHP code execution. Nexcess proactively notified affected customers and recommended updating to the patched releases (7.0.3, 6.9.6, 6.8.7, or equivalent supported branch versions), with automatic security updates delivering fixes to eligible sites. The incident was resolved on September 2, 2026, with no evidence of widespread exploitation reported throughout the disclosure period.

A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution. Impacted versions: WordPress 4.7 – 7.0.2 (every release on every branch) WordPress 4.6 and earlier — end of life, no patch available Fixed versions: WordPress 7.0.3 WordPress 6.9.6 WordPress 6.8.7 Equivalent minor releases on every remaining supported branch back to 4.7 Recommended Action Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links. Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version. There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please contact our Support team.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 19 days ago - at 09/02/2026 08:33PM

The WordPress security vulnerability CVE-2026-64638 has been addressed in the latest WordPress security releases.

Customers are encouraged to keep their WordPress installations updated to the latest available security release within their current supported branch.

We have proactively contacted customers identified as running potentially affected WordPress versions and provided recommendations to update their installations.

At this time, the incident has been resolved, and the related status page notification will be closed.

INVESTIGATING about 1 month ago - at 08/08/2026 01:28PM

A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.

Impacted versions:
WordPress 4.7 – 7.0.2 (every release on every branch)
WordPress 4.6 and earlier — end of life, no patch available

Fixed versions:
WordPress 7.0.3
WordPress 6.9.6
WordPress 6.8.7
Equivalent minor releases on every remaining supported branch back to 4.7


Recommended Action
Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Since exploitation requires user interaction, customers should also remain vigilant against phishing attempts and avoid clicking suspicious or unsolicited links.
Customers with automatic security updates enabled should receive the applicable update automatically; however, we recommend verifying the currently running WordPress version.
There is currently no reported evidence of widespread exploitation in the wild. We will continue to monitor the situation and provide further updates if required.

If you need assistance or have any concerns, please contact our Support team.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook