CVE Tools
Back to feed
Patch released WordPress patch-tuesday rce

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

Patchstack·By Chazz Wolcott··5 min read
CVE Tools coverage

On August 6, 2026, WordPress released version 7.0.3 to address 12 security issues ranging from reflected and stored cross-site scripting (XSS) to privilege escalation, server-side request forgery (SSRF), and more. Among the notable fixes is a high-risk unauthenticated XSS flaw that could lead to remote code execution if triggered by an administrator clicking a malicious link. Other vulnerabilities include several stored XSS risks requiring contributor-level access, as well as a privilege escalation issue affecting Multisite setups. Patchstack has implemented real-time protections for these critical flaws, but administrators are strongly advised to upgrade to 7.0.3 immediately to ensure full mitigation.

WordPress 7.0.3 landed on 6 August 2026. It’s a security release with 12 different fixes covering pre-auth cross-site scripting (XSS), stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass, and server-side request forgery.

Patchstack deployed RapidMitigate rules for the high-risk vulnerabilities immediately. We still recommend updating to the most recent version of WordPress available.…

Continue reading on Patchstack