{"id":2597,"date":"2026-08-06T18:55:30","date_gmt":"2026-08-06T18:55:30","guid":{"rendered":"https:\/\/mailurdu.co.uk\/?p=2597"},"modified":"2026-08-06T18:55:30","modified_gmt":"2026-08-06T18:55:30","slug":"wordpress-org-blog-wordpress-7-0-3-release","status":"publish","type":"post","link":"https:\/\/mailurdu.co.uk\/?p=2597","title":{"rendered":"WordPress.org blog: WordPress 7.0.3 release"},"content":{"rendered":"<h1 class=\"wp-block-heading\">WordPress 7.0.3 is now available<\/h1>\n<p class=\"wp-block-paragraph\">WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.<\/p>\n<p class=\"wp-block-paragraph\">You can update to WordPress 7.0.3 by <a href=\"https:\/\/wordpress.org\/wordpress-7.0.3.zip\">downloading it from WordPress.org<\/a>, or visiting your site\u2019s Dashboard \u2192 Updates and clicking <strong>Update Now<\/strong>. Sites that support automatic background updates will begin updating shortly.<\/p>\n<p class=\"wp-block-paragraph\">For more information, please visit the <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/\">WordPress 7.0.3 HelpHub site<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release:<\/p>\n<ul class=\"wp-block-list\">\n<li>Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at <a href=\"https:\/\/pwn.ai\/\">pwn.ai<\/a>.<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (<a href=\"https:\/\/hackerone.com\/amosec?type=user\">amosec<\/a>)<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by <a href=\"https:\/\/hackerone.com\/n05ec\">n05ec<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by <a href=\"https:\/\/www.linkedin.com\/in\/naveens72\/\">Naveen S<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/ajmalmoochingal\/\">Ajmal Moochingal<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by <a href=\"https:\/\/profiles.wordpress.org\/xknown\/\">Alex Concha<\/a> of the WordPress Security Team<\/li>\n<li>A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by <a href=\"https:\/\/aikido.dev\/\">Aikido Security<\/a><\/li>\n<li>An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by <a href=\"https:\/\/profiles.wordpress.org\/ehtis\/\">Ehtisham Siddiqui<\/a> of the WordPress Security Team<\/li>\n<li>Enumeration of post slugs reported by <a href=\"https:\/\/hdwsec.fr\/\">HDWSec<\/a><\/li>\n<li>Disclosure of notes in comment feeds reported by <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\/\">Elio Gubser<\/a><\/li>\n<li>Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic<\/li>\n<li>Bypass of the email address confirmation flow reported by <a href=\"https:\/\/hackerone.com\/0ways\">0ways<\/a><\/li>\n<li>A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by <a href=\"https:\/\/hackerone.com\/andrewmohawk?type=user\">Andrew Mohawk<\/a> and multiple independent reporters<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n<p class=\"wp-block-paragraph\">WordPress 7.1 RC2 has also been released, containing all applicable fixes.<\/p>\n<h2 class=\"wp-block-heading\">CVE and GHSA references<\/h2>\n<p class=\"wp-block-paragraph\">Details of the login screen XSS vulnerability can be found in the advisory: <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-52p2-r8wf-jcrf\">CVE-2026-64638 \/ GHSA-52p2-r8wf-jcrf<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\">John Blackbourn<\/a>. In addition to the security researchers mentioned above, WordPress 7.0.3 and its backports would not have been possible without the significant contributions of the following people:<br \/><a href=\"https:\/\/profiles.wordpress.org\/aaroncampbell\">Aaron D. Campbell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorbin\">Aaron Jorbin<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adamsilverstein\">Adam Silverstein<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adrianmoldovanwp\">adrianmoldovanwp<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/wildworks\">Aki Hamano<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/xknown\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/aduth\">Andrew Duthie<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andrewserong\">Andrew Serong<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/annezazu\">annezazu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/barry\">Barry<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bernhard-reiter\">Bernie Reiter<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/villanovachile\">Daniel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbinda\">David Bi\u0148ovec<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dmsnell\">Dennis Snell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ehtis\">Ehtisham Siddiqui<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/erwanlr\">Erwan Le Rousseau<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fabiankaegy\/\">Fabian Kaegy<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fiocavallari\">fiocavallari<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mamaduka\">George Mamadashvili<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\">gubser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/isabel_brison\">Isabel Brison<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jsnajdr\">Jarda Snajdr<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jeremyfelt\">Jeremy Felt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joedolson\">Joe Dolson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joehoyle\">Joe Hoyle<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonsurrell\">Jon Surrell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/khokansardar\">Khokan Sardar<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lancewillett\">Lance Willett<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucasbustamante\">lucasbustamante<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucatume\">lucatume<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mciampini\/\">Marco Ciampini<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tyxla\">Marin Atanasov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/batmoo\">Mohammad Jangda<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paulkevan\">Paul Kevan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ramonopoly\">ramonopoly<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\">SergeyBiryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vortfu\">vortfu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/westonruter\">Weston Ruter<\/a><\/p>\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-image size-large has-custom-border\"><a href=\"https:\/\/us.wordcamp.org\/2026\/\" rel=\" noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" alt=\"WordCamp US: Powered by WordPress, Driven by Community, August 16-19, 2026\" class=\"wp-image-20859\" height=\"321\" src=\"https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser.png?resize=1024%2C321&amp;ssl=1\" width=\"1024\"\/><\/a><figcaption class=\"wp-element-caption\">Join us for the launch of WordPress 7.1 at <a href=\"https:\/\/us.wordcamp.org\/2026\/\">WordCamp US 2026<\/a>, August 16\u201319.<\/figcaption><\/figure>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from <a class=\"read-more\" href=\"https:\/\/mailurdu.co.uk\/?p=2597\">\u0645\u0632\u06cc\u062f \u067e\u0691\u06be\u06cc\u06ba<\/a><\/p>\n","protected":false},"author":1,"featured_media":2598,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pakistan"],"_links":{"self":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2597"}],"version-history":[{"count":0,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2597\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/media\/2598"}],"wp:attachment":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}