Twelve vulnerabilities exposed across WordPress 4.7 to 7.0.2
WordPress released 7.0.3 on 6 August 2026, fixing twelve separate vulnerabilities. The most serious, CVE-2026-64638, is a pre-authentication flaw on the login screen rated 8.9 out of 10, and it affects every version of WordPress released since 2016. Update to 7.0.3, 6.9.6 or 6.8.7. This arrives three weeks after the WP2Shell chain, and that pattern matters more than any single item on the list.