WordPress 7.0.3
Breaking: WordPress 7.0.3 ships today. This is a security release — update immediately.
WordPress 7.0.3, released August 6, 2026, patches 13 reported vulnerabilities and backports fixes to every supported branch (back through 4.7). The release was led by John Blackbourn.
Security Fixes
Fixed in this release:
- Pre-auth reflected XSS on the login screen — with potential to lead to PHP code execution (CVE-2026-64638 / GHSA-52p2-r8wf-jcrf), reported by the team at pwn.ai
- Stored XSS in posts via the emoji settings element, reported by Asaf Mozes
- Stored XSS in the Post Content block, reported by n05ec
- Stored XSS in Quick Edit on sites with a large number of users, reported by Naveen S and Ajmal Moochingal
- Stored XSS in the Post Date block, reported by Alex Concha
- Privilege escalation on multisite networks with user registration enabled, reported by Aikido Security
- Information disclosure in the Latest Comments block exposing comments on password-protected posts
- Post slug enumeration, reported by HDWSec
- Disclosure of notes in comment feeds, reported by Elio Gubser
- CSS injection via bypass of the safe CSS attribute filter (Author+), reported by Anthropic
- Bypass of the email address confirmation flow, reported by 0ways
- SSRF in URL validation allowing requests to link-local ranges, reported by Andrew Mohawk and multiple independent reporters
Action Required
Update now. Visit Dashboard → Updates and click Update Now, or download from WordPress.org. Sites with automatic background updates enabled will begin updating shortly.
WordPress 7.1 RC2 has also been released and contains all applicable fixes.