WP
WordPress Core 7.0.3
Get release alerts
7.0.2โ7.0.3SecurityBug fix
โฆ Editor's summary
WordPress 7.0.3 is a security-focused maintenance release for the WordPress 7.0 branch. The update addresses multiple security vulnerabilities in WordPress Core and is recommended for prompt deployment on affected websites. This release follows WordPress 7.0.2, which was itself an urgent security update.
โ Security impact
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.
Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by N05ec@LZU
Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
Enumeration of post slugs reported by HDWSec
Disclosure of notes in comment feeds reported by Elio Gubser
Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
Bypass of the email address confirmation flow reported by Omar Hasan
A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
What's new
- WordPress Core 7.0.3 has been released โ see the official changelog for details.
More from WordPress Core
๐ฌ Comments (0)
Share any installation issues, compatibility changes, or fixes you noticed.