As cited
Copy frozen at (site build).
vulnerabilities
WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed
WordPress 7.0.3 released August 6, 2026, patches 12 vulnerabilities including a pre-authentication reflected XSS on the login screen (CVE-2026-64638) that can lead to remote code execution if an administrator clicks a malicious link, four stored XSS bugs requiring contributor-level access, and issues in multisite privilege escalation, information disclosure, CSS injection, email verification, and server-side request forgery. The release highlights a shift in vulnerability discovery: artificial intelligence (AI) models like GPT-5.6 Sol and autonomous pentesting tools now identify exploitable flaws in hours rather than through manual review, with WordPress HackerOne reports jumping to 450 in July from historical monthly counts in the dozens.
Why it matters: Site administrators should patch immediately to close the pre-auth XSS-to-RCE chain, and those running multisite installations with user registration or contributor-heavy sites with guest authors need urgent updates; the acceleration of AI-driven vulnerability discovery means the window between disclosure and active exploitation has compressed from days to hours, making delayed patching increasingly risky.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed
WordPress 7.0.3 released August 6, 2026, patches 12 vulnerabilities including a pre-authentication reflected XSS on the login screen (CVE-2026-64638) that can lead to remote code execution if an administrator clicks a malicious link, four stored XSS bugs requiring contributor-level access, and issues in multisite privilege escalation, information disclosure, CSS injection, email verification, and server-side request forgery. The release highlights a shift in vulnerability discovery: artificial intelligence (AI) models like GPT-5.6 Sol and autonomous pentesting tools now identify exploitable flaws in hours rather than through manual review, with WordPress HackerOne reports jumping to 450 in July from historical monthly counts in the dozens.
Why it matters: Site administrators should patch immediately to close the pre-auth XSS-to-RCE chain, and those running multisite installations with user registration or contributor-heavy sites with guest authors need urgent updates; the acceleration of AI-driven vulnerability discovery means the window between disclosure and active exploitation has compressed from days to hours, making delayed patching increasingly risky.
- Source published
- First seen by Cybersecurity Tracker