August Was a Patch Month. The Hard Part Is Updating the Fleet.

August 2026 was busy on the core side.

WordPress 7.0.3 landed on 6 August with a pre-auth login-screen XSS (CVE-2026-64638) that can chain to PHP execution, plus a pile of contributor-level XSS fixes. WordPress 7.0.4 followed on 12 August for an author-level remote code execution path through a malicious Postscript upload when Imagick and Ghostscript are on the box (CVE-2026-65640). Joomla 6.1.3 and 5.4.8, released 18 August, closed ten core issues including an MFA authentication bypass and unrestricted SHTML uploads.

The advisory is the easy part. If you look after more than a handful of WordPress and Joomla sites, the real work is knowing which ones actually took the update, which ones failed halfway, and whether you have a backup that lives off the same disk.

Clicking Update on twenty logins is how things get missed. A tracked update workflow is slower in the first five minutes and faster for the rest of the month.

That is what I built CMS Inspect for. One dashboard for WordPress and Joomla fleets: safer updates with a clearer audit trail, uptime, database and file backups to Google Drive or Dropbox, security triage, Analytics linking, and client reports. The core is free. Advanced ops is $1 per active site a month.

Patch when the project says so. Then check the fleet, not your memory.

CMS Inspect

Sources: