Available for New Projects
Web Development

Two Critical WordPress Vulnerabilities Patched in August 2026 — Update Your Dubai Site Now

Two Critical WordPress Vulnerabilities Patched in August 2026 — Update Your Dubai Site Now
Published 20 Aug, 2026 Web Development 4 min read

Two WordPress core security releases landed within a week of each other in August 2026, and if your site hasn’t been updated since before the 6th, it’s running with a publicly known, high-severity vulnerability sitting in the login page. This is the kind of update the 2025 security checklist on this site already tells you to stay on top of. Consider this the specific, dated reason to actually go check right now rather than filing it under “eventually.”

What Got Patched

WordPress 7.0.3 (August 6, 2026) fixed 12 separate vulnerabilities in one release: a pre-authentication cross-site scripting issue, stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass, and server-side request forgery among them. One vulnerability in that batch stands out specifically: a reflected XSS in the login page (wp-login.php) affecting every WordPress release, rated High severity with a CVSS score of 8.9. It requires no authentication and no existing session to exploit. An attacker only needs to get a target to click a crafted link, and the resulting JavaScript execution can be used to harvest credentials, steal session tokens, or make requests as if they were the logged-in user.

WordPress 7.0.4 (August 12, 2026) followed six days later with additional fixes, including an authenticated Author-level remote code execution vulnerability triggered through a malicious file upload, specifically on sites that have Imagick and Ghostscript installed. That combination is common enough on managed WordPress hosting that it’s worth checking rather than assuming it doesn’t apply to you.


What This Actually Means for Your Site

The wp-login.php vulnerability is the more urgent one specifically because it needs no authentication at all, every WordPress site running an unpatched version is exposed regardless of how strong your admin password is or how few user accounts exist. A phishing link or a compromised ad network serving the crafted URL is all it takes to trigger it against a visitor or an admin who clicks through.

The Author-level RCE is more contained, it requires an existing Author-or-above account on the site, but for any site where you allow client logins, guest contributors, or multiple content editors, that’s a real access level to have on your site already, not a hypothetical attacker profile.


What to Do Right Now

  • Check your current WordPress version in wp-admin under Dashboard > Updates, or ask whoever manages your hosting to confirm it directly.
  • Update to 7.0.4 immediately if you’re on anything earlier. This is a security release, not a routine version bump, treat it with the urgency that implies.
  • Check whether Imagick and Ghostscript are installed on your server if you’re not sure, and confirm the update specifically addresses the RCE path for your setup.
  • Review who actually has Author-level access or above on your site while you’re in there. Fewer standing high-privilege accounts means less exposure the next time a vulnerability like this surfaces.

Frequently Asked Questions

Check Dashboard > Updates in wp-admin, or the WordPress version listed in Site Health under Tools. If it shows 7.0.4 or later, you’re current on these specific fixes.
Security releases carry lower compatibility risk than major version updates, but testing on staging before updating production is still good practice, especially if you’re running custom plugins or an older theme. If you don’t have a staging environment, that’s worth setting up regardless of this specific update.
Depends entirely on your host. Some managed hosting providers apply security updates automatically; others leave it to the site owner. Confirm directly with your host which applies to your account rather than assuming.

Not Sure If Your Site Is Actually Protected?

If you manage your own WordPress site and aren’t confident it’s actually current on security patches, a free hosting audit will tell you exactly where you stand, this vulnerability included.

Book your free hosting audit at as86.pro — bilingual service in English and Arabic across all UAE markets.

Related reading:

Amir Sibaee

Written by Amir Sibaee

Google Ads & Media Buying Specialist · SEO/SEM · Marketing Automation ·...

More about Amir →

Get a Growth Plan, Not Just a Quote

Seeking expert digital marketing, web design, or graphic design in the UAE? Let's discuss your project and deliver tailored solutions for measurable growth.

Book Free Consultation