{"id":12025,"date":"2026-08-07T00:25:30","date_gmt":"2026-08-06T18:55:30","guid":{"rendered":"https:\/\/4ksamachar.com\/?p=12025"},"modified":"2026-08-07T00:25:30","modified_gmt":"2026-08-06T18:55:30","slug":"wordpress-org-blog-wordpress-7-0-3-release","status":"publish","type":"post","link":"https:\/\/4ksamachar.com\/?p=12025","title":{"rendered":"WordPress.org blog: WordPress 7.0.3 release"},"content":{"rendered":"<h1 class=\"wp-block-heading\">WordPress 7.0.3 is now available<\/h1>\n<p class=\"wp-block-paragraph\">WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.<\/p>\n<p class=\"wp-block-paragraph\">You can update to WordPress 7.0.3 by <a href=\"https:\/\/wordpress.org\/wordpress-7.0.3.zip\" target=\"_blank\" rel=\"noopener\">downloading it from WordPress.org<\/a>, or visiting your site\u2019s Dashboard \u2192 Updates and clicking <strong>Update Now<\/strong>. Sites that support automatic background updates will begin updating shortly.<\/p>\n<p class=\"wp-block-paragraph\">For more information, please visit the <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/\" target=\"_blank\" rel=\"noopener\">WordPress 7.0.3 HelpHub site<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release:<\/p>\n<ul class=\"wp-block-list\">\n<li>Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (<a href=\"https:\/\/hackerone.com\/amosec?type=user\" target=\"_blank\" rel=\"noopener\">amosec<\/a>)<\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by <a href=\"https:\/\/hackerone.com\/n05ec\" target=\"_blank\" rel=\"noopener\">n05ec<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by <a href=\"https:\/\/www.linkedin.com\/in\/naveens72\/\" target=\"_blank\" rel=\"noopener\">Naveen S<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/ajmalmoochingal\/\" target=\"_blank\" rel=\"noopener\">Ajmal Moochingal<\/a><\/li>\n<li>Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by <a href=\"https:\/\/profiles.wordpress.org\/xknown\/\" target=\"_blank\" rel=\"noopener\">Alex Concha<\/a> of the WordPress Security Team<\/li>\n<li>A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by <a href=\"https:\/\/aikido.dev\/\" target=\"_blank\" rel=\"noopener\">Aikido Security<\/a><\/li>\n<li>An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by <a href=\"https:\/\/profiles.wordpress.org\/ehtis\/\" target=\"_blank\" rel=\"noopener\">Ehtisham Siddiqui<\/a> of the WordPress Security Team<\/li>\n<li>Enumeration of post slugs reported by <a href=\"https:\/\/hdwsec.fr\/\" target=\"_blank\" rel=\"noopener\">HDWSec<\/a><\/li>\n<li>Disclosure of notes in comment feeds reported by <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\/\" target=\"_blank\" rel=\"noopener\">Elio Gubser<\/a><\/li>\n<li>Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic<\/li>\n<li>Bypass of the email address confirmation flow reported by <a href=\"https:\/\/hackerone.com\/0ways\" target=\"_blank\" rel=\"noopener\">0ways<\/a><\/li>\n<li>A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by <a href=\"https:\/\/hackerone.com\/andrewmohawk?type=user\" target=\"_blank\" rel=\"noopener\">Andrew Mohawk<\/a> and multiple independent reporters<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n<p class=\"wp-block-paragraph\">WordPress 7.1 RC2 has also been released, containing all applicable fixes.<\/p>\n<h2 class=\"wp-block-heading\">CVE and GHSA references<\/h2>\n<p class=\"wp-block-paragraph\">Details of the login screen XSS vulnerability can be found in the advisory: <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-52p2-r8wf-jcrf\" target=\"_blank\" rel=\"noopener\">CVE-2026-64638 \/ GHSA-52p2-r8wf-jcrf<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\" target=\"_blank\" rel=\"noopener\">John Blackbourn<\/a>. In addition to the security researchers mentioned above, WordPress 7.0.3 and its backports would not have been possible without the significant contributions of the following people:<br \/><a href=\"https:\/\/profiles.wordpress.org\/aaroncampbell\" target=\"_blank\" rel=\"noopener\">Aaron D. Campbell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorbin\" target=\"_blank\" rel=\"noopener\">Aaron Jorbin<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adamsilverstein\" target=\"_blank\" rel=\"noopener\">Adam Silverstein<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adrianmoldovanwp\" target=\"_blank\" rel=\"noopener\">adrianmoldovanwp<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/wildworks\" target=\"_blank\" rel=\"noopener\">Aki Hamano<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/xknown\" target=\"_blank\" rel=\"noopener\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/aduth\" target=\"_blank\" rel=\"noopener\">Andrew Duthie<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andrewserong\" target=\"_blank\" rel=\"noopener\">Andrew Serong<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/annezazu\" target=\"_blank\" rel=\"noopener\">annezazu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/barry\" target=\"_blank\" rel=\"noopener\">Barry<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bernhard-reiter\" target=\"_blank\" rel=\"noopener\">Bernie Reiter<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/villanovachile\" target=\"_blank\" rel=\"noopener\">Daniel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\" target=\"_blank\" rel=\"noopener\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbinda\" target=\"_blank\" rel=\"noopener\">David Bi\u0148ovec<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dmsnell\" target=\"_blank\" rel=\"noopener\">Dennis Snell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ehtis\" target=\"_blank\" rel=\"noopener\">Ehtisham Siddiqui<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/erwanlr\" target=\"_blank\" rel=\"noopener\">Erwan Le Rousseau<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fabiankaegy\/\" target=\"_blank\" rel=\"noopener\">Fabian Kaegy<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/fiocavallari\" target=\"_blank\" rel=\"noopener\">fiocavallari<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mamaduka\" target=\"_blank\" rel=\"noopener\">George Mamadashvili<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/odkdn1\" target=\"_blank\" rel=\"noopener\">gubser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/isabel_brison\" target=\"_blank\" rel=\"noopener\">Isabel Brison<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jsnajdr\" target=\"_blank\" rel=\"noopener\">Jarda Snajdr<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\" target=\"_blank\" rel=\"noopener\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jeremyfelt\" target=\"_blank\" rel=\"noopener\">Jeremy Felt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joedolson\" target=\"_blank\" rel=\"noopener\">Joe Dolson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joehoyle\" target=\"_blank\" rel=\"noopener\">Joe Hoyle<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\" target=\"_blank\" rel=\"noopener\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonsurrell\" target=\"_blank\" rel=\"noopener\">Jon Surrell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\" target=\"_blank\" rel=\"noopener\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/khokansardar\" target=\"_blank\" rel=\"noopener\">Khokan Sardar<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lancewillett\" target=\"_blank\" rel=\"noopener\">Lance Willett<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucasbustamante\" target=\"_blank\" rel=\"noopener\">lucasbustamante<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/lucatume\" target=\"_blank\" rel=\"noopener\">lucatume<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mciampini\/\" target=\"_blank\" rel=\"noopener\">Marco Ciampini<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tyxla\" target=\"_blank\" rel=\"noopener\">Marin Atanasov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/batmoo\" target=\"_blank\" rel=\"noopener\">Mohammad Jangda<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\" target=\"_blank\" rel=\"noopener\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paulkevan\" target=\"_blank\" rel=\"noopener\">Paul Kevan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\" target=\"_blank\" rel=\"noopener\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ramonopoly\" target=\"_blank\" rel=\"noopener\">ramonopoly<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\" target=\"_blank\" rel=\"noopener\">SergeyBiryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vortfu\" target=\"_blank\" rel=\"noopener\">vortfu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/westonruter\" target=\"_blank\" rel=\"noopener\">Weston Ruter<\/a><\/p>\n<div class=\"wp-block-group is-layout-constrained wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-image size-large has-custom-border\"><a href=\"https:\/\/us.wordcamp.org\/2026\/\" rel=\" noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" alt=\"WordCamp US: Powered by WordPress, Driven by Community, August 16-19, 2026\" class=\"wp-image-20859\" height=\"321\" src=\"https:\/\/i0.wp.com\/wordpress.org\/news\/files\/2026\/06\/wcus-2026-teaser.png?resize=1024%2C321&amp;ssl=1\" width=\"1024\"><\/a><figcaption class=\"wp-element-caption\">Join us for the launch of WordPress 7.1 at <a href=\"https:\/\/us.wordcamp.org\/2026\/\" target=\"_blank\" rel=\"noopener\">WordCamp US 2026<\/a>, August 16\u201319.<\/figcaption><\/figure>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site\u2019s Dashboard \u2192 Updates and clicking Update Now. Sites that support [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12026,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-12025","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blog_post_layout_featured_media_urls":{"thumbnail":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-150x150.png",150,150,true],"full":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx.png",1024,321,false]},"categories_names":{"1":{"name":"Uncategorized","link":"https:\/\/4ksamachar.com\/?cat=1"}},"tags_names":[],"comments_number":"0","wpmagazine_modules_lite_featured_media_urls":{"thumbnail":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-150x150.png",150,150,true],"cvmm-medium":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-300x300.png",300,300,true],"cvmm-medium-plus":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-305x207.png",305,207,true],"cvmm-portrait":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-400x321.png",400,321,true],"cvmm-medium-square":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-600x321.png",600,321,true],"cvmm-large":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx.png",1024,321,false],"cvmm-small":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx-130x95.png",130,95,true],"full":["https:\/\/4ksamachar.com\/wp-content\/uploads\/2026\/08\/wcus-2026-teaser-5bRllx.png",1024,321,false]},"_links":{"self":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts\/12025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12025"}],"version-history":[{"count":0,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts\/12025\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/media\/12026"}],"wp:attachment":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}