CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6276

As cited

Copy frozen at (site build).

vulnerabilities

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

WordPress 7.0.3 released August 6, 2026, patches 12 vulnerabilities including a pre-authentication reflected XSS on the login screen (CVE-2026-64638) that can lead to remote code execution if an administrator clicks a malicious link, four stored XSS bugs requiring contributor-level access, and issues in multisite privilege escalation, information disclosure, CSS injection, email verification, and server-side request forgery. The release highlights a shift in vulnerability discovery: artificial intelligence (AI) models like GPT-5.6 Sol and autonomous pentesting tools now identify exploitable flaws in hours rather than through manual review, with WordPress HackerOne reports jumping to 450 in July from historical monthly counts in the dozens.

Why it matters: Site administrators should patch immediately to close the pre-auth XSS-to-RCE chain, and those running multisite installations with user registration or contributor-heavy sites with guest authors need urgent updates; the acceleration of AI-driven vulnerability discovery means the window between disclosure and active exploitation has compressed from days to hours, making delayed patching increasingly risky.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

WordPress 7.0.3 released August 6, 2026, patches 12 vulnerabilities including a pre-authentication reflected XSS on the login screen (CVE-2026-64638) that can lead to remote code execution if an administrator clicks a malicious link, four stored XSS bugs requiring contributor-level access, and issues in multisite privilege escalation, information disclosure, CSS injection, email verification, and server-side request forgery. The release highlights a shift in vulnerability discovery: artificial intelligence (AI) models like GPT-5.6 Sol and autonomous pentesting tools now identify exploitable flaws in hours rather than through manual review, with WordPress HackerOne reports jumping to 450 in July from historical monthly counts in the dozens.

Why it matters: Site administrators should patch immediately to close the pre-auth XSS-to-RCE chain, and those running multisite installations with user registration or contributor-heavy sites with guest authors need urgent updates; the acceleration of AI-driven vulnerability discovery means the window between disclosure and active exploitation has compressed from days to hours, making delayed patching increasingly risky.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary