Title: Version 7.0.3
Author: Lance Willett
Published: August 6, 2026

---

# Version 7.0.3

## In this article

 * [Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#installation-update-information)
 * [Summary](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#summary)
    - [Security updates](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#security-updates)
 * [Change log](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#change-log)
    - [List of files revised](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#list-of-files-revised)
    - [List of packages revised](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#list-of-packages-revised)

[ Back to top](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#wp--skip-link--target)

On August 6, 2026, WordPress 7.0.3 was released to the public.

## 󠀁[Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#installation-update-information)󠁿

To get this version, update automatically from the Dashboard > Updates menu in your
site’s admin area or visit [https://wordpress.org/download/releases/](https://wordpress.org/download/releases/).

For step-by-step instructions on installing and updating WordPress:

 * [Updating WordPress](https://wordpress.org/documentation/article/updating-wordpress/)

If you are new to WordPress, we recommend that you begin with the following:

 * [Get Started With WordPress](https://wordpress.org/documentation/article/get-started-with-wordpress/)
 * [First Steps With WordPress](https://wordpress.org/documentation/article/first-steps-with-wordpress-classic/)
   or [Upgrading WordPress Extended](https://developer.wordpress.org/advanced-administration/upgrade/upgrading/)
 * [WordPress Courses](https://learn.wordpress.org/courses/)

## 󠀁[Summary](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#summary)󠁿

### 󠀁[Security updates](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#security-updates)󠁿

This release features several security fixes. Because this is a security release,**
it is recommended that you update your sites immediately.**
The security team would
like to thank the following people for [responsibly reporting vulnerabilities](https://hackerone.com/wordpress?type=team),
and allowing them to be fixed in this release:

 * A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block
   reported by Alex Concha of the WordPress Security Team
 * A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block
   reported by n05ec
 * An information disclosure issue in the Latest Comments block exposing comments
   on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security
   Team
 * A bypass of the email address confirmation flow reported by 0ways
 * An Author+ CSS injection issue via a bypass of the safe CSS attribute filter 
   reported by Anthropic
 * A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji
   settings element reported by Asaf Mozes (amosec)
 * A privilege escalation issue on multisite networks with user registration enabled,
   allowing a user to create a new site reported by Aikido Security
 * A server-side request forgery (SSRF) issue in URL validation allowing requests
   to link-local ranges reported by Andrew Mohawk and multiple independent reporters
 * A pre-auth reflected cross-site scripting (XSS) issue on the login screen with
   potential to lead to PHP code execution reported by the team at pwn.ai
 * A disclosure of notes in comment feeds reported by Elio Gubser
 * An enumeration of post slugs reported by HDWSec
 * A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites
   with a large number of users reported by Naveen S and Ajmal Moochingal

As a courtesy, these fixes are also available in older affected branches of WordPress.
As a reminder, **only the most recent version of WordPress is actively supported.**

 * WordPress 6.9 is affected by 11 of the 12 vulnerabilities. [Version 6.9.6](https://wordpress.org/documentation/wordpress-version/version-6-9-6/)
   has been released containing fixes.
 * WordPress 6.8 is affected by 8 of the 12 vulnerabilities. [Version 6.8.7](https://wordpress.org/documentation/wordpress-version/version-6-8-7/)
   has been released containing fixes.
 * WordPress 6.7 is affected by 8 of the 12 vulnerabilities. [Version 6.7.6](https://wordpress.org/documentation/wordpress-version/version-6-7-6/)
   has been released containing fixes.
 * WordPress 6.6 is affected by 8 of the 12 vulnerabilities. [Version 6.6.6](https://wordpress.org/documentation/wordpress-version/version-6-6-6/)
   has been released containing fixes.
 * WordPress 6.5 is affected by 8 of the 12 vulnerabilities. [Version 6.5.9](https://wordpress.org/documentation/wordpress-version/version-6-5-9/)
   has been released containing fixes.
 * WordPress 6.4 is affected by 8 of the 12 vulnerabilities. [Version 6.4.9](https://wordpress.org/documentation/wordpress-version/version-6-4-9/)
   has been released containing fixes.
 * WordPress 6.3 is affected by 8 of the 12 vulnerabilities. [Version 6.3.9](https://wordpress.org/documentation/wordpress-version/version-6-3-9/)
   has been released containing fixes.
 * WordPress 6.2 is affected by 8 of the 12 vulnerabilities. [Version 6.2.10](https://wordpress.org/documentation/wordpress-version/version-6-2-10/)
   has been released containing fixes.
 * WordPress 6.1 is affected by 8 of the 12 vulnerabilities. [Version 6.1.11](https://wordpress.org/documentation/wordpress-version/version-6-1-11/)
   has been released containing fixes.
 * WordPress 6.0 is affected by 8 of the 12 vulnerabilities. [Version 6.0.13](https://wordpress.org/documentation/wordpress-version/version-6-0-13/)
   has been released containing fixes.
 * WordPress 5.9 is affected by 8 of the 12 vulnerabilities. [Version 5.9.14](https://wordpress.org/documentation/wordpress-version/version-5-9-14/)
   has been released containing fixes.
 * WordPress 5.8 is affected by 8 of the 12 vulnerabilities. [Version 5.8.14](https://wordpress.org/documentation/wordpress-version/version-5-8-14/)
   has been released containing fixes.
 * WordPress 5.7 is affected by 7 of the 12 vulnerabilities. [Version 5.7.16](https://wordpress.org/documentation/wordpress-version/version-5-7-16/)
   has been released containing fixes.
 * WordPress 5.6 is affected by 7 of the 12 vulnerabilities. [Version 5.6.18](https://wordpress.org/documentation/wordpress-version/version-5-6-18/)
   has been released containing fixes.
 * WordPress 5.5 is affected by 7 of the 12 vulnerabilities. [Version 5.5.19](https://wordpress.org/documentation/wordpress-version/version-5-5-19/)
   has been released containing fixes.
 * WordPress 5.4 is affected by 7 of the 12 vulnerabilities. [Version 5.4.20](https://wordpress.org/documentation/wordpress-version/version-5-4-20/)
   has been released containing fixes.
 * WordPress 5.3 is affected by 7 of the 12 vulnerabilities. [Version 5.3.22](https://wordpress.org/documentation/wordpress-version/version-5-3-22/)
   has been released containing fixes.
 * WordPress 5.2 is affected by 7 of the 12 vulnerabilities. [Version 5.2.25](https://wordpress.org/documentation/wordpress-version/version-5-2-25/)
   has been released containing fixes.
 * WordPress 5.1 is affected by 7 of the 12 vulnerabilities. [Version 5.1.23](https://wordpress.org/documentation/wordpress-version/version-5-1-23/)
   has been released containing fixes.
 * WordPress 5.0 is affected by 7 of the 12 vulnerabilities. [Version 5.0.26](https://wordpress.org/documentation/wordpress-version/version-5-0-26/)
   has been released containing fixes.
 * WordPress 4.9 is affected by 7 of the 12 vulnerabilities. [Version 4.9.30](https://wordpress.org/documentation/wordpress-version/version-4-9-30/)
   has been released containing fixes.
 * WordPress 4.8 is affected by 7 of the 12 vulnerabilities. [Version 4.8.29](https://wordpress.org/documentation/wordpress-version/version-4-8-29/)
   has been released containing fixes.
 * WordPress 4.7 is affected by 7 of the 12 vulnerabilities. [Version 4.7.34](https://wordpress.org/documentation/wordpress-version/version-4-7-34/)
   has been released containing fixes.
 * WordPress 4.6 and earlier no longer receive security updates.

## 󠀁[Change log](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#change-log)󠁿

### 󠀁[List of files revised](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#list-of-files-revised)󠁿

    ```wp-block-preformatted
    /wp-admin/includes/user.php/wp-admin/js/inline-edit-post.js/wp-includes/canonical.php/wp-includes/class-wp-script-modules.php/wp-includes/http.php/wp-includes/js/wp-emoji-loader.js/wp-includes/kses.php/wp-includes/user.php/wp-login.php/wp-signup.php
    ```

### 󠀁[List of packages revised](https://wordpress.org/documentation/wordpress-version/version-7-0-3/?output_format=md#list-of-packages-revised)󠁿

No package was revised.

First published

August 6, 2026

Last updated