WordPress 7.0.4 is now available

WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately.

You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support automatic background updates will begin updating shortly.

For more information, please visit the WordPress 7.0.4 HelpHub site.

Security update included in this release

The security team would like to thank the team at pwn.ai for responsibly reporting the following vulnerability and allowing it to be fixed in this release:

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript.

Backports

As a courtesy, these fixes are being backported through to the 4.7 branch and the 7.1 RC3 release that’s due later today. As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.

CVE and GHSA references

Further details can be found in the advisory: CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w.

Thank you to these WordPress contributors

This release was led by John Blackbourn, with significant input from Dennis Snell and Jeremy Felt. In addition, WordPress 7.0.4 and its backports would not have been possible without the valuable contributions of the following people:

Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, Aki Hamano, Alex Concha, Barry, Dennis Snell, Ehtisham Siddiqui, Jeremy Felt, John Blackbourn, Jonathan Desrosiers, Lance Willett, Marin Atanasov, Mohammad Jangda, Sergey Biryukov, vortfu, Weston Ruter, and representatives from WP Engine.

Compartilhar.
Deixe Uma Resposta

Português do Brasil
Exit mobile version