WordPress 7.0.4 is now out there
WordPress 7.0.4 is now out there which encompasses a safety repair. Because this can be a safety launch, it is strongly recommended that you just replace your websites instantly.
You can replace to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your website’s Dashboard → Updates and clicking Update Now. Sites that assist automated background updates will start updating shortly.
For extra data, please go to the WordPress 7.0.4 HelpHub website.
Security replace included on this launch
The safety group want to thank the group at pwn.ai for responsibly reporting the next vulnerability and permitting it to be fastened on this launch:
- Authenticated Author+ distant code execution through malicious file add on websites that use Imagick and Ghostscript.
Backports
As a courtesy, these fixes are being backported by way of to the 4.7 department and the 7.1 RC3 launch that’s due later in the present day. As a reminder, solely the newest model of WordPress is actively supported. The backports are in progress and can ship as they turn out to be prepared.
CVE and GHSA references
Further particulars will be discovered within the advisory: CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w.
Thank you to those WordPress contributors
This launch was led by John Blackbourn, with important enter from Dennis Snell and Jeremy Felt. In addition, WordPress 7.0.4 and its backports wouldn’t have been potential with out the precious contributions of the next folks:
Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, Aki Hamano, Alex Concha, Barry, Dennis Snell, Ehtisham Siddiqui, Jeremy Felt, John Blackbourn, Jonathan Desrosiers, Lance Willett, Marin Atanasov, Mohammad Jangda, Sergey Biryukov, vortfu, Weston Ruter, and representatives from WP Engine.
