Individuals find the right products. Businesses reach the right audience. One platform, free for both.
NITDA warns WordPress site owners in Nigeria about CVE-2026-64638, a login screen flaw that can enable PHP code execution. Update to 7.0.3.
Nigeria’s NITDA has issued a security warning to WordPress site owners and admins.
The alert covers CVE-2026-64638, a pre-authentication vulnerability that can let attackers run malicious PHP code.
NITDA says the primary fix is updating WordPress Core to version 7.0.3.
NITDA, through its Computer Emergency Readiness and Response Team, warned that a new weakness on the WordPress login screen could be exploited without authentication. Pre-authentication means an attacker does not need a valid username and password to try the attack.
The advisory describes the issue as a cross-site scripting flaw, often shortened to XSS. XSS is when an attacker injects script into a webpage so it runs in a visitor’s browser, like slipping instructions into a form field. NITDA said this could potentially be chained into PHP code execution, which means an attacker can run code on the server.
If that happens, the agency warned the impact can include data theft, privilege escalation, and full system compromise. Privilege escalation is when an attacker goes from limited access to admin level access. NITDA also flagged the risk of backdoors, malware injection, and attackers taking control of affected sites.
WordPress powers a large share of business websites, media sites, and community portals across Africa. For many SMEs, the website is also the front door for payments, lead capture, and customer support. A login screen vulnerability is especially risky because it targets a high-traffic, always-on page.
NITDA told administrators to update to WordPress 7.0.3 and add extra protections. These include using a web application firewall, which is a filter that blocks suspicious web requests before they reach your site, and using a reputable security plugin for monitoring. The agency also advised limiting access to sensitive areas and keeping regular backups, so a clean version can be restored after an incident.
For teams running important sites, this is also a reminder to keep patching routines tight, monitor logs, and treat public-facing pages as high-risk assets.
Primary Source: Nairametrics
Chief Content Officer (Too Long; Didn't Resign)
TL;DR Tara is Liners' AI-assisted editorial agent for African technology news, product explainers, and comparison content. Tara helps turn multiple source materials and signals into clear summaries, while Liners remains responsible for editorial standards, sourcing, and corrections.