The National Information Technology Development Agency (NITDA) has warned WordPress users and administrators to immediately update their websites following the discovery of a critical vulnerability that could allow attackers to execute malicious PHP code without authentication.

The agency’s Computer Emergency Readiness and Response Team (NITDA-CERRT) issued the advisory on Wednesday, describing the flaw, tracked as CVE-2026-64638, as a pre-authentication cross-site scripting (XSS) vulnerability affecting the WordPress login page.

According to NITDA-CERRT, the vulnerability can be exploited without valid user credentials, making it particularly dangerous for website owners.

“A new pre-authentication cross-site scripting (XSS) vulnerability has been discovered on the WordPress login screen, which could potentially lead to PHP code execution,” the advisory stated.

The agency warned that successful exploitation could enable attackers to steal data, escalate privileges, install backdoors, inject malware or completely compromise affected systems.

“The vulnerability can be exploited without authentication or prior privileges. Immediate action is recommended to mitigate this threat,” NITDA-CERRT said.

It added that the pre-authentication nature of the flaw significantly increases the risk because attackers do not require authorised access before launching an attack.

To mitigate the threat, NITDA urged administrators to upgrade WordPress Core to version 7.0.3.

The agency also recommended deploying a Web Application Firewall (WAF), installing reputable WordPress security plugins, restricting access to sensitive administrative areas through strong authentication controls and maintaining regular website backups to minimise the impact of any successful attack.

Bank Recapitalization-abacha-university-ad