NITDA warns WordPress users over vulnerability that could give attackers website control
Nigeria’s National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites. The post NITDA warns WordPress users over vulnerability that could give attackers website control appeared first on Nairametrics .
Nigeria's National Information Technology Development Agency (NITDA) has issued a warning to WordPress users and administrators regarding a pre-authentication vulnerability, which could enable attackers to gain control of affected websites. The vulnerability, tracked as CVE-2026-64638, was highlighted in an advisory from the NITDA Computer Emergency Readiness and Response Team (NITDA-CERRT) on Wednesday.
The agency advised WordPress administrators to update to WordPress Core version 7.0.3 and implement additional security measures to protect their websites. This pre-authentication flaw specifically affects the WordPress login screen and could lead to unauthorized access, data theft, privilege escalation, and full system compromise if exploited.
An attacker could potentially execute malicious PHP code, create backdoors, inject malware, or take control of an affected system. NITDA-CERRT emphasized the importance of updating WordPress Core as the primary mitigation strategy and recommended regular backups to minimize potential data loss in case of a compromise. The agency has previously warned about vulnerabilities in widely used WordPress components, with a previous 2024 warning focusing on a different flaw in a WordPress plugin.
NITDA is also working to strengthen Nigeria's cloud computing ecosystem through various regulatory instruments and the National Sovereign Cloud Initiative.
Written by urgent.news from Nairametrics's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.