Important correction: The previous article's CVE identifier, WordPress 7.0.4 claim, and Imagick/Ghostscript RCE claim were not supported by the cited page or WordPress's official releases. The cited news page was unrelated to WordPress. Those claims are withdrawn.
What WordPress officially released
WordPress 7.0.2 was published on July 17, 2026. The official announcement lists CVE-2026-60137, a stored cross-site scripting issue requiring an authenticated Contributor or higher role, and CVE-2026-63030, an information-disclosure issue through post titles requiring an authenticated Contributor.
Affected branches and action
Fixes are included in WordPress 7.0.2, 6.9.5, and 6.8.6. The official release says branches before 6.8 are unaffected. Back up the site, update to the appropriate fixed release or later, and test editing, themes, and critical plugins.
- ✓Check the installed core version in Dashboard > Updates or with WP-CLI
- ✓Back up files and the database
- ✓Install the appropriate fixed branch or later
- ✓Review Contributor-or-higher accounts and unexpected content changes
wp core version
wp core check-update