Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN832
_____________________________________________________________________

DATE                : 10/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running WordPress versions prior to 7.0.3.
 
=====================================================================
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
_____________________________________________________________________

WordPress 7.0.3 is now available

WordPress 7.0.3 is now available which features several security
fixes. Because this is a security release, it is recommended that you
update your sites immediately.

You can update to WordPress 7.0.3 by downloading it from WordPress.org,
or visiting your site’s Dashboard → Updates and clicking Update Now.
Sites that support automatic background updates will begin updating
shortly.

For more information, please visit the WordPress 7.0.3 HelpHub site.
Security updates included in this release

The security team would like to thank the following people for
responsibly reporting vulnerabilities and allowing them to be fixed
in this release:

    Pre-auth reflected cross-site scripting (XSS) on the login screen
with potential to lead to PHP code execution reported by the team at
pwn.ai.
    Contributor+ stored cross-site scripting (XSS) in posts via the
emoji settings element reported by Asaf Mozes (amosec)
    Contributor+ stored cross-site scripting (XSS) in the Post
Content block reported by N05ec@LZU
    Contributor+ stored cross-site scripting (XSS) in Quick Edit on
sites with a large number of users reported by Naveen S and Ajmal
Moochingal
    Contributor+ stored cross-site scripting (XSS) in the Post Date
block reported by Alex Concha of the WordPress Security Team
    A privilege escalation issue on multisite networks with user
registration enabled, allowing a user to create a new site reported
by Aikido Security
    An information disclosure issue in the Latest Comments block
exposing comments on password-protected posts reported by Ehtisham
Siddiqui of the WordPress Security Team
    Enumeration of post slugs reported by HDWSec
    Disclosure of notes in comment feeds reported by Elio Gubser
    Author+ CSS injection via a bypass of the safe CSS attribute
filter reported by Anthropic
    Bypass of the email address confirmation flow reported by Omar Hasan
    A server-side request forgery (SSRF) issue in URL validation
allowing requests to link-local ranges reported by Andrew Mohawk
and multiple independent reporters


Backports

As a courtesy, these fixes are being backported, where necessary,
to all branches eligible to receive security fixes (currently
through 4.7). As a reminder, only the most recent version of
WordPress is actively supported. The backports are in progress
and will ship as they become ready.

WordPress 7.1 RC2 has also been released, containing all
applicable fixes.


CVE and GHSA references

Details of the login screen XSS vulnerability can be found in the
advisory: CVE-2026-64638 / GHSA-52p2-r8wf-jcrf.

Thank you to these WordPress contributors

This release was led by John Blackbourn. In addition to the security
researchers mentioned above, WordPress 7.0.3 and its backports would
not have been possible without the significant contributions of the
following people:

Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, adrianmoldovanwp,
Aki Hamano, Alex Concha, Andrew Duthie, Andrew Serong, annezazu,
Barry, Bernie Reiter, Daniel, Daniel Richards, David Biňovec,
Dennis Snell, Ehtisham Siddiqui, Erwan Le Rousseau, Fabian Kaegy,
fiocavallari, George Mamadashvili, gubser, Isabel Brison,
Jarda Snajdr, Jb Audras, Jeremy Felt, Joe Dolson, Joe Hoyle,
John Blackbourn, Jon Surrell, Jonathan Desrosiers, Khokan Sardar,
Lance Willett, lucasbustamante, lucatume, Marco Ciampini,
Marin Atanasov, Mohammad Jangda, Mukesh Panchal, Paul Kevan,
Peter Wilson, ramonopoly, SergeyBiryukov, vortfu, Weston Ruter

_____________________________________________________________________


Pre-auth reflected XSS on login screen with potential to lead to PHP
code execution

High
johnbillion published GHSA-52p2-r8wf-jcrf

Package
WordPress (WordPress)

Affected versions
7.0.0 - 7.0.2
6.9.0 - 6.9.5
6.8.0 - 6.8.6
6.7.0 - 6.7.5
6.6.0 - 6.6.5
6.5.0 - 6.5.8
6.4.0 - 6.4.8
6.3.0 - 6.3.8
6.2.0 - 6.2.9
6.1.0 - 6.1.10
6.0.0 - 6.0.12
5.9.0 - 5.9.13
5.8.0 - 5.8.13
5.7.0 - 5.7.15
5.6.0 - 5.6.17
5.5.0 - 5.5.18
5.4.0 - 5.4.19
5.3.0 - 5.3.21
5.2.0 - 5.2.24
5.1.0 - 5.1.22
5.0.0 - 5.0.25
4.9.0 - 4.9.29
4.8.0 - 4.8.28
4.7.0 - 4.7.33

Patched versions
7.0.3
6.9.6
6.8.7
6.7.6
6.6.6
6.5.9
6.4.9
6.3.9
6.2.10
6.1.11
6.0.13
5.9.14
5.8.14
5.7.16
5.6.18
5.5.19
5.4.20
5.3.22
5.2.25
5.1.23
5.0.26
4.9.30
4.8.29
4.7.34


Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the
login screen.

Via a specially crafted malicious third-party website hosted by an attacker,
it is possible for this to be escalated to an RCE vulnerability with
conditions outside of the attackers control. This requires successful
social engineering of and explicit interaction by the target victim.

This issue affects all versions of WordPress. Version 7.0.3 has been
released, containing a fix for the vulnerability, and as a courtesy to
users on older branches the fix has been backported to all branches
back to 4.7.

Discovered and responsibly disclosed by the team at pwn.ai.

Full information about the WordPress 7.0.3 release can be found here:
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/.


Severity
High
8.9/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity High
Attack Requirements None
Privileges Required None
User interaction Active
Vulnerable System Impact Metrics
Confidentiality High
Integrity High
Availability High
Subsequent System Impact Metrics
Confidentiality High
Integrity High
Availability High
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVE ID
CVE-2026-64638

Weaknesses
No CWEs


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




