CVE Tools

WordPress 7.0.3 Released: 12 Vulnerabilities Found and Fixed

PatchstackBy Chazz Wolcott5 min read

PatchWordPress

Our summary

On August 6, 2026, WordPress released version 7.0.3 to address 12 security issues ranging from reflected and stored cross-site scripting (XSS) to privilege escalation, server-side request forgery (SSRF), and more. Among the notable fixes is a high-risk unauthenticated XSS flaw that could lead to remote code execution if triggered by an administrator clicking a malicious link. Other vulnerabilities include several stored XSS risks requiring contributor-level access, as well as a privilege escalation issue affecting Multisite setups. Patchstack has implemented real-time protections for these critical flaws, but administrators are strongly advised to upgrade to 7.0.3 immediately to ensure full mitigation.

Read at Patchstack

Below is the opening; the full story is at Patchstack.

From Patchstack

WordPress 7.0.3 landed on 6 August 2026. It’s a security release with 12 different fixes covering pre-auth cross-site scripting (XSS), stored XSS, privilege escalation, information disclosure, CSS injection, an email verification bypass, and server-side request forgery.

Patchstack deployed RapidMitigate rules for the high-risk vulnerabilities immediately. We still recommend updating to the most recent version of WordPress available.…

Continue at Patchstack

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store