Live / Incidents / Liquid Web
Liquid Web: Security Advisory: WordPress XSS2Shell Vulnerability (CVE-2026-64638)
Liquid Web · liquidweb.comImpact: noneResolved2026-08-08 13:24 UTC
Public — what happened
Summary
A high-severity reflected XSS vulnerability, CVE-2026-64638, has been identified in the WordPress login interface. Exploitation requires a victim to visit a specially crafted URL and, under specific conditions, could potentially lead to PHP code execution.
Impacted versions
Impacted versions:
WordPress 4.7 – 7.0.2 (every release on every branch)
WordPress 4.6 and earlier — end of life, no patch available
Fixed versions:
WordPress 7.0.3
WordPress 6.9.6
WordPress 6.8.7
Equivalent minor releases on every remaining supported branch back to 4.7
Recommended Action
Customers are strongly encouraged to update WordPress core and ensure automatic security updates are enabled where appropriate. Si
Timeline
- Started — 2026-08-08 13:24 UTC
- Last update — 2026-08-08 13:24 UTC
- Resolved — 2026-09-03 14:15 UTC
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Liquid Web against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Liquid Web: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Liquid Web report →