{"id":16369701,"date":"2026-08-06T18:50:21","date_gmt":"2026-08-06T18:50:21","guid":{"rendered":"https:\/\/wordpress.org\/documentation\/?post_type=helphub_version&#038;p=16369701"},"modified":"2026-08-06T18:50:21","modified_gmt":"2026-08-06T18:50:21","slug":"version-7-0-3","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/","title":{"rendered":"Version 7.0.3"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On August 6, 2026, WordPress 7.0.3 was released to the public.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit <a href=\"https:\/\/wordpress.org\/download\/releases\/\">https:\/\/wordpress.org\/download\/releases\/<\/a>.<br>For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/get-started-with-wordpress\/\">Get Started With WordPress<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/first-steps-with-wordpress-classic\/\">First Steps With WordPress<\/a> or <a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/upgrade\/upgrading\/\">Upgrading WordPress Extended<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.wordpress.org\/courses\/\">WordPress Courses<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Security updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This release features several security fixes. Because this is a security release, <strong>it is recommended that you update your sites immediately.<\/strong><br>The security team would like to thank the following people for <a href=\"https:\/\/hackerone.com\/wordpress?type=team\">responsibly reporting vulnerabilities<\/a>, and allowing them to be fixed in this release:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block reported by Alex Concha of the WordPress Security Team<\/li>\n\n\n\n<li>A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block reported by n05ec<\/li>\n\n\n\n<li>An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team<\/li>\n\n\n\n<li>A bypass of the email address confirmation flow reported by 0ways<\/li>\n\n\n\n<li>An Author+ CSS injection issue via a bypass of the safe CSS attribute filter reported by Anthropic<\/li>\n\n\n\n<li>A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element reported by Asaf Mozes (amosec)<\/li>\n\n\n\n<li>A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security<\/li>\n\n\n\n<li>A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters<\/li>\n\n\n\n<li>A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai<\/li>\n\n\n\n<li>A disclosure of notes in comment feeds reported by Elio Gubser<\/li>\n\n\n\n<li>An enumeration of post slugs reported by HDWSec<\/li>\n\n\n\n<li>A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, <strong>only the most recent version of WordPress is actively supported.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress 6.9 is affected by 11 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-6\/\">Version 6.9.6<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.8 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-8-7\/\">Version 6.8.7<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.7 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-7-6\/\">Version 6.7.6<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.6 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-6-6\/\">Version 6.6.6<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.5 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-5-9\/\">Version 6.5.9<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.4 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-4-9\/\">Version 6.4.9<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.3 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-3-9\/\">Version 6.3.9<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.2 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-2-10\/\">Version 6.2.10<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.1 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-1-11\/\">Version 6.1.11<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.0 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-0-13\/\">Version 6.0.13<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.9 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-9-14\/\">Version 5.9.14<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.8 is affected by 8 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-8-14\/\">Version 5.8.14<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.7 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-7-16\/\">Version 5.7.16<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.6 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-6-18\/\">Version 5.6.18<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.5 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-5-19\/\">Version 5.5.19<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.4 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-4-20\/\">Version 5.4.20<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.3 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-3-22\/\">Version 5.3.22<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.2 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-2-25\/\">Version 5.2.25<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.1 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-1-23\/\">Version 5.1.23<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.0 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-0-26\/\">Version 5.0.26<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.9 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-9-30\/\">Version 4.9.30<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.8 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-8-29\/\">Version 4.8.29<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.7 is affected by 7 of the 12 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-7-34\/\">Version 4.7.34<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.6 and earlier no longer receive security updates.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Change log<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">List of files revised<\/h3>\n\n\n\n<pre class=\"wp-block-preformatted\">\/wp-admin\/includes\/user.php<br>\/wp-admin\/js\/inline-edit-post.js<br>\/wp-includes\/canonical.php<br>\/wp-includes\/class-wp-script-modules.php<br>\/wp-includes\/http.php<br>\/wp-includes\/js\/wp-emoji-loader.js<br>\/wp-includes\/kses.php<br>\/wp-includes\/user.php<br>\/wp-login.php<br>\/wp-signup.php<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">List of packages revised<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No package was revised.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>On August 6, 2026, WordPress 7.0.3 was released to the public. Installation\/Update Information To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit https:\/\/wordpress.org\/download\/releases\/.For step-by-step instructions on installing and updating WordPress: If you are new to WordPress, we recommend that you begin with the following: Summary [&hellip;]<\/p>\n","protected":false},"author":2097165,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false},"helphub_major_release":[],"class_list":["post-16369701","helphub_version","type-helphub_version","status-publish","hentry"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16369701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/2097165"}],"version-history":[{"count":9,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16369701\/revisions"}],"predecessor-version":[{"id":16369782,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16369701\/revisions\/16369782"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=16369701"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=16369701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}