{"id":21327,"date":"2026-08-06T18:55:30","date_gmt":"2026-08-06T18:55:30","guid":{"rendered":"https:\/\/wordpress.org\/news\/?p=21327"},"modified":"2026-08-07T09:50:53","modified_gmt":"2026-08-07T09:50:53","slug":"wordpress-7-0-3-release","status":"publish","type":"post","link":"https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-3-release\/","title":{"rendered":"WordPress 7.0.3 release"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">WordPress 7.0.3 is now available<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can update to WordPress 7.0.3 by <a href=\"https:\/\/wordpress.org\/wordpress-7.0.3.zip\">downloading it from WordPress.org<\/a>, or visiting your site&#8217;s Dashboard \u2192 Updates and clicking <strong>Update Now<\/strong>. Sites that support automatic background updates will begin updating shortly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please visit the <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/\">WordPress 7.0.3 HelpHub site<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at <a href=\"https:\/\/pwn.ai\/\">pwn.ai<\/a>.<\/li>\n\n\n\n<li>Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (<a href=\"https:\/\/hackerone.com\/amosec?type=user\">amosec<\/a>)<\/li>\n\n\n\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by <a href=\"https:\/\/hackerone.com\/n05ec\">N05ec@LZU<\/a><\/li>\n\n\n\n<li>Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by <a href=\"https:\/\/www.linkedin.com\/in\/naveens72\/\">Naveen S<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/ajmalmoochingal\/\">Ajmal Moochingal<\/a><\/li>\n\n\n\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by <a href=\"https:\/\/profiles.wordpress.org\/xknown\/\">Alex Concha<\/a> of the WordPress Security Team<\/li>\n\n\n\n<li>A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by <a href=\"https:\/\/aikido.dev\/\">Aikido Security<\/a><\/li>\n\n\n\n<li>An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by <a href=\"https:\/\/profiles.wordpress.org\/ehtis\/\">Ehtisham Siddiqui<\/a> of the WordPress Security Team<\/li>\n\n\n\n<li>Enumeration of post slugs reported by <a href=\"https:\/\/hdwsec.fr\/\">HDWSec<\/a><\/li>\n\n\n\n<li>Disclosure of notes in comment feeds reported by <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\/\">Elio Gubser<\/a><\/li>\n\n\n\n<li>Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic<\/li>\n\n\n\n<li>Bypass of the email address confirmation flow reported by <a href=\"https:\/\/www.linkedin.com\/in\/omr-h\/\">Omar Hasan<\/a><\/li>\n\n\n\n<li>A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by <a href=\"https:\/\/hackerone.com\/andrewmohawk?type=user\">Andrew Mohawk<\/a> and multiple independent reporters<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 7.1 RC2 has also been released, containing all applicable fixes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CVE and GHSA references<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Details of the login screen XSS vulnerability can be found in the advisory: <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-52p2-r8wf-jcrf\">CVE-2026-64638 \/ GHSA-52p2-r8wf-jcrf<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\">John Blackbourn<\/a>. In addition to the security researchers mentioned above, WordPress 7.0.3 and its backports would not have been possible without the significant contributions of the following people:<br><a href=\"https:\/\/profiles.wordpress.org\/aaroncampbell\">Aaron D. Campbell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorbin\">Aaron Jorbin<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adamsilverstein\">Adam Silverstein<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adrianmoldovanwp\">adrianmoldovanwp<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/wildworks\">Aki Hamano<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/xknown\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/aduth\">Andrew Duthie<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andrewserong\">Andrew Serong<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/annezazu\">annezazu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/barry\">Barry<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bernhard-reiter\">Bernie Reiter<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/villanovachile\">Daniel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbinda\">David Bi\u0148ovec<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dmsnell\">Dennis Snell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ehtis\">Ehtisham Siddiqui<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/erwanlr\">Erwan Le Rousseau<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fabiankaegy\/\">Fabian Kaegy<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fiocavallari\">fiocavallari<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mamaduka\">George Mamadashvili<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\">gubser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/isabel_brison\">Isabel Brison<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jsnajdr\">Jarda Snajdr<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jeremyfelt\">Jeremy Felt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joedolson\">Joe Dolson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joehoyle\">Joe Hoyle<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonsurrell\">Jon Surrell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/khokansardar\">Khokan Sardar<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lancewillett\">Lance Willett<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucasbustamante\">lucasbustamante<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucatume\">lucatume<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mciampini\/\">Marco Ciampini<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tyxla\">Marin Atanasov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/batmoo\">Mohammad Jangda<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paulkevan\">Paul Kevan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ramonopoly\">ramonopoly<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\">SergeyBiryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vortfu\">vortfu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/westonruter\">Weston Ruter<\/a><\/p>\n\n\n\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-image size-large has-custom-border\"><a href=\"https:\/\/us.wordcamp.org\/2026\/\" target=\"_blank\" rel=\" noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"321\" src=\"https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser.png?resize=1024%2C321&#038;ssl=1\" alt=\"WordCamp US: Powered by WordPress, Driven by Community, August 16-19, 2026\" class=\"wp-image-20859\" style=\"border-style:none;border-width:0px;border-top-left-radius:2px;border-top-right-radius:2px;border-bottom-left-radius:2px;border-bottom-right-radius:2px;box-shadow:var(--wp--preset--shadow--natural)\" srcset=\"https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser-scaled.png?resize=1024%2C321&amp;ssl=1 1024w, https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser-scaled.png?resize=300%2C94&amp;ssl=1 300w, https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser-scaled.png?resize=768%2C241&amp;ssl=1 768w, https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser-scaled.png?resize=1536%2C482&amp;ssl=1 1536w, https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser-scaled.png?resize=2048%2C643&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><figcaption class=\"wp-element-caption\">Join us for the launch of WordPress 7.1 at <a href=\"https:\/\/us.wordcamp.org\/2026\/\">WordCamp US 2026<\/a>, August 16\u201319.<\/figcaption><\/figure>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site&#8217;s Dashboard \u2192 Updates and clicking Update Now. Sites that support [&hellip;]<\/p>\n","protected":false},"author":42547,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"episode_type":"","audio_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[14,15],"tags":[437,409],"class_list":["post-21327","post","type-post","status-publish","format-standard","hentry","category-releases","category-security","tag-minor-releases","tag-releases"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pZhYe-5xZ","_links":{"self":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/21327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/users\/42547"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/comments?post=21327"}],"version-history":[{"count":7,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/21327\/revisions"}],"predecessor-version":[{"id":21339,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/21327\/revisions\/21339"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/media?parent=21327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/categories?post=21327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/tags?post=21327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}