They were already knocking
A bare address with no WordPress on it logged 1,371 WordPress-shaped requests from 70 networks, 38 of them against wp-login.php. CVE-2026-64638 is a pre-authentication flaw on exactly that page, scored 8.9, affecting every release from 4.7 to 7.0 and fixed in 7.0.3.
One thousand three hundred and seventy-one WordPress requests, on a server that has never run WordPress.
A new flaw is announced and the question is how quickly anyone would find you. The logs already answer that.
This address hosts nothing. No site, no domain, no install. It still took thirteen hundred WordPress-shaped requests from seventy networks.
A hundred and eighty-three asked for the installer. Thirty-eight went to the login page.
That login page is where the new one lives. Pre-authentication, no account needed, scored eight point nine. It affects every release from four point seven up to seven point zero — about nine years of them — and it is fixed in seven point oh three.
Nobody has to discover you. That traffic is already arriving, on an address with nothing worth attacking.
Update to seven point oh three. That page is never quiet.
#linux#security#wordpress#infosec#sysadmin
❯ Update to 7.0.3. The page it lives on is never quiet.