PhrasePress 7.0.3 is now out there
PhrasePress 7.0.3 is now out there which options a number of safety fixes. Because it is a safety release, it is strongly recommended that you just replace your websites instantly.
You can replace to PhrasePress 7.0.3 by downloading it from PhrasePress.org, or visiting your web site’s Dashboard → Updates and clicking Update Now. Sites that help computerized background updates will start updating shortly.
For extra data, please go to the PhrasePress 7.0.3 HelpHub web site.
Security updates included on this release
The safety staff wish to thank the next individuals for responsibly reporting vulnerabilities and permitting them to be fastened on this release:
- Pre-auth mirrored cross-site scripting (XSS) on the login display with potential to result in PHP code execution reported by the staff at pwn.ai.
- Contributor+ saved cross-site scripting (XSS) in posts through the emoji settings aspect reported by Asaf Mozes (amosec)
- Contributor+ saved cross-site scripting (XSS) within the Post Content block reported by n05ec
- Contributor+ saved cross-site scripting (XSS) in Quick Edit on websites with numerous customers reported by Naveen S and Ajmal Moochingal
- Contributor+ saved cross-site scripting (XSS) within the Post Date block reported by Alex Concha of the PhrasePress Security Team
- A privilege escalation subject on multisite networks with person registration enabled, permitting a person to create a brand new web site reported by Aikido Security
- An data disclosure subject within the Latest Comments block exposing feedback on password-protected posts reported by Ehtisham Siddiqui of the PhrasePress Security Team
- Enumeration of submit slugs reported by HDWSec
- Disclosure of notes in remark feeds reported by Elio Gubser
- Author+ CSS injection through a bypass of the secure CSS attribute filter reported by Anthropic
- Bypass of the e-mail tackle affirmation stream reported by 0ways
- A server-side request forgery (SSRF) subject in URL validation permitting requests to link-local ranges reported by Andrew Mohawk and a number of impartial reporters
Backports
As a courtesy, these fixes are being backported, the place obligatory, to all branches eligible to obtain safety fixes (at the moment by way of 4.7). As a reminder, solely the latest model of PhrasePress is actively supported. The backports are in progress and can ship as they develop into prepared.
PhrasePress 7.1 RC2 has additionally been launched, containing all relevant fixes.
CVE and GHSA references
Details of the login display XSS vulnerability may be discovered within the advisory: CVE-2026-64638 / GHSA-52p2-r8wf-jcrf.
Thank you to those PhrasePress contributors
This release was led by John Blackbourn. In addition to the safety researchers talked about above, PhrasePress 7.0.3 and its backports wouldn’t have been potential with out the numerous contributions of the next individuals:
Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, adrianmoldovanwp, Aki Hamano, Alex Concha, Andrew Duthie, Andrew Serong, annezazu, Barry, Bernie Reiter, Daniel, Daniel Richards, David Biňovec, Dennis Snell, Ehtisham Siddiqui, Erwan Le Rousseau, Fabian Kaegy, fiocavallari, George Mamadashvili, gubser, Isabel Brison, Jarda Snajdr, Jb Audras, Jeremy Felt, Joe Dolson, Joe Hoyle, John Blackbourn, Jon Surrell, Jonathan Desrosiers, Khokan Sardar, Lance Willett, lucasbustamante, lucatume, Marco Ciampini, Marin Atanasov, Mohammad Jangda, Mukesh Panchal, Paul Kevan, Peter Wilson, ramonopoly, SergeyBiryukov, vortfu, Weston Ruter


