Two Critical WordPress Vulnerabilities Patched in August 2026 — Update Your Dubai Site Now
Two WordPress core security releases landed within a week of each other in August 2026, and if your site hasn’t been updated since before the 6th, it’s running with a publicly known, high-severity vulnerability sitting in the login page. This is the kind of update the 2025 security checklist on this site already tells you to stay on top of. Consider this the specific, dated reason to actually go check right now rather than filing it under “eventually.”
What Got Patched
WordPress 7.0.3 (August 6, 2026) fixed 12 separate vulnerabilities in one release: a pre-authentication cross-site scripting issue, stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass, and server-side request forgery among them. One vulnerability in that batch stands out specifically: a reflected XSS in the login page (wp-login.php) affecting every WordPress release, rated High severity with a CVSS score of 8.9. It requires no authentication and no existing session to exploit. An attacker only needs to get a target to click a crafted link, and the resulting JavaScript execution can be used to harvest credentials, steal session tokens, or make requests as if they were the logged-in user.
WordPress 7.0.4 (August 12, 2026) followed six days later with additional fixes, including an authenticated Author-level remote code execution vulnerability triggered through a malicious file upload, specifically on sites that have Imagick and Ghostscript installed. That combination is common enough on managed WordPress hosting that it’s worth checking rather than assuming it doesn’t apply to you.
What This Actually Means for Your Site
The wp-login.php vulnerability is the more urgent one specifically because it needs no authentication at all, every WordPress site running an unpatched version is exposed regardless of how strong your admin password is or how few user accounts exist. A phishing link or a compromised ad network serving the crafted URL is all it takes to trigger it against a visitor or an admin who clicks through.
The Author-level RCE is more contained, it requires an existing Author-or-above account on the site, but for any site where you allow client logins, guest contributors, or multiple content editors, that’s a real access level to have on your site already, not a hypothetical attacker profile.
What to Do Right Now
- Check your current WordPress version in wp-admin under Dashboard > Updates, or ask whoever manages your hosting to confirm it directly.
- Update to 7.0.4 immediately if you’re on anything earlier. This is a security release, not a routine version bump, treat it with the urgency that implies.
- Check whether Imagick and Ghostscript are installed on your server if you’re not sure, and confirm the update specifically addresses the RCE path for your setup.
- Review who actually has Author-level access or above on your site while you’re in there. Fewer standing high-privilege accounts means less exposure the next time a vulnerability like this surfaces.
Frequently Asked Questions
Not Sure If Your Site Is Actually Protected?
If you manage your own WordPress site and aren’t confident it’s actually current on security patches, a free hosting audit will tell you exactly where you stand, this vulnerability included.
Book your free hosting audit at as86.pro — bilingual service in English and Arabic across all UAE markets.
Related reading:
Written by Amir Sibaee
Google Ads & Media Buying Specialist · SEO/SEM · Marketing Automation ·...
More about Amir →Latest Posts
-
Performance Max in 2026: Asset Experiments, New Audience Exclusions, and What Actually Changed
-
Should You Let an AI Agent Run Your Ad Campaigns? A Dubai Marketer’s Honest Take
-
AI Overviews vs AI Mode: What Changed in Google Search in 2026 (And What Dubai Businesses Should Do About It)
-
Google Ads Is Removing Language Targeting From Search in September 2026 & What It Means for Your EN/AR Campaigns
-
Google Says GEO Isn't a Separate Strategy From SEO— What That Actually Means for Dubai Businesses
-
PPC Management in Abu Dhabi: What's Actually Different From Dubai (And Why Most Agencies Get It Wrong)
-
Klaviyo MCP + Claude AI: The Official Connector Setup Guide for Dubai E-commerce Brands
-
Google Ads AI Max Takeover: What Dubai Advertisers Must Do Before Dynamic Search Ads Disappear in September 2026
-
7,281 WhatsApp Conversations, AED 7.51 CPL: What Ezee Hire's Meta Ads Campaign Got Right
-
From 83,000 Conversions to AED 0.95 CPL: The Google Ads Playbook Behind the Ezee Hire Case Study
Get a Growth Plan, Not Just a Quote
Seeking expert digital marketing, web design, or graphic design in the UAE? Let's discuss your project and deliver tailored solutions for measurable growth.
Book Free Consultation