{"id":62938,"date":"2026-08-06T15:18:49","date_gmt":"2026-08-06T19:18:49","guid":{"rendered":"https:\/\/bowlingquest.com\/?p=62938"},"modified":"2026-08-06T15:18:49","modified_gmt":"2026-08-06T19:18:49","slug":"wordpress-org-blog-wordpress-7-0-3-release","status":"publish","type":"post","link":"https:\/\/bowlingquest.com\/?p=62938","title":{"rendered":"WordPress.org blog: WordPress 7.0.3 release"},"content":{"rendered":"<h1 class=\"wp-block-heading\">WordPress 7.0.3 is now available<\/h1>\n<p class=\"wp-block-paragraph\">WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.<\/p>\n<p class=\"wp-block-paragraph\">You can update to WordPress 7.0.3 by <a href=\"https:\/\/wordpress.org\/wordpress-7.0.3.zip\">downloading it from WordPress.org<\/a>, or visiting your site\u2019s Dashboard \u2192 Updates and clicking <strong>Update Now<\/strong>. Sites that support automatic background updates will begin updating shortly.<\/p>\n<p class=\"wp-block-paragraph\">For more information, please visit the <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/\">WordPress 7.0.3 HelpHub site<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release:<\/p>\n<ul class=\"wp-block-list\">\n<li>Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (<a href=\"https:\/\/hackerone.com\/amosec?type=user\">amosec<\/a>)<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by <a href=\"https:\/\/hackerone.com\/n05ec\">n05ec<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by <a href=\"https:\/\/www.linkedin.com\/in\/naveens72\/\">Naveen S<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/ajmalmoochingal\/\">Ajmal Moochingal<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by <a href=\"https:\/\/profiles.wordpress.org\/xknown\/\">Alex Concha<\/a> of the WordPress Security Team<\/li>\n<li>A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by <a href=\"https:\/\/aikido.dev\/\">Aikido Security<\/a><\/li>\n<li>An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by <a href=\"https:\/\/profiles.wordpress.org\/ehtis\/\">Ehtisham Siddiqui<\/a> of the WordPress Security Team<\/li>\n<li>Enumeration of post slugs reported by <a href=\"https:\/\/hdwsec.fr\/\">HDWSec<\/a><\/li>\n<li>Disclosure of notes in comment feeds reported by <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\/\">Elio Gubser<\/a><\/li>\n<li>Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic<\/li>\n<li>Bypass of the email address confirmation flow reported by <a href=\"https:\/\/hackerone.com\/0ways\">0ways<\/a><\/li>\n<li>A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by <a href=\"https:\/\/hackerone.com\/andrewmohawk?type=user\">Andrew Mohawk<\/a> and multiple independent reporters<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n<p class=\"wp-block-paragraph\">WordPress 7.1 RC2 has also been released, containing all applicable fixes.<\/p>\n<h2 class=\"wp-block-heading\">CVE and GHSA references<\/h2>\n<p class=\"wp-block-paragraph\">Details of the login screen XSS vulnerability can be found in the advisory: <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-52p2-r8wf-jcrf\">CVE-2026-64638 \/ GHSA-52p2-r8wf-jcrf<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\">John Blackbourn<\/a>. In addition to the security researchers mentioned above, WordPress 7.0.3 and its backports would not have been possible without the significant contributions of the following people:<br \/><a href=\"https:\/\/profiles.wordpress.org\/aaroncampbell\">Aaron D. Campbell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorbin\">Aaron Jorbin<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adamsilverstein\">Adam Silverstein<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adrianmoldovanwp\">adrianmoldovanwp<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/wildworks\">Aki Hamano<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/xknown\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/aduth\">Andrew Duthie<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andrewserong\">Andrew Serong<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/annezazu\">annezazu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/barry\">Barry<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bernhard-reiter\">Bernie Reiter<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/villanovachile\">Daniel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbinda\">David Bi\u0148ovec<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dmsnell\">Dennis Snell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ehtis\">Ehtisham Siddiqui<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/erwanlr\">Erwan Le Rousseau<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fabiankaegy\/\">Fabian Kaegy<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fiocavallari\">fiocavallari<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mamaduka\">George Mamadashvili<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\">gubser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/isabel_brison\">Isabel Brison<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jsnajdr\">Jarda Snajdr<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jeremyfelt\">Jeremy Felt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joedolson\">Joe Dolson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joehoyle\">Joe Hoyle<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonsurrell\">Jon Surrell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/khokansardar\">Khokan Sardar<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lancewillett\">Lance Willett<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucasbustamante\">lucasbustamante<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucatume\">lucatume<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mciampini\/\">Marco Ciampini<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tyxla\">Marin Atanasov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/batmoo\">Mohammad Jangda<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paulkevan\">Paul Kevan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ramonopoly\">ramonopoly<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vortfu\">vortfu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/westonruter\">Weston Ruter<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from &hellip; <a href=\"https:\/\/bowlingquest.com\/?p=62938\">Continued<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-62938","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/bowlingquest.com\/index.php?rest_route=\/wp\/v2\/posts\/62938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bowlingquest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bowlingquest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bowlingquest.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bowlingquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=62938"}],"version-history":[{"count":0,"href":"https:\/\/bowlingquest.com\/index.php?rest_route=\/wp\/v2\/posts\/62938\/revisions"}],"wp:attachment":[{"href":"https:\/\/bowlingquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=62938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bowlingquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=62938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bowlingquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=62938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}