Skip to content

security: update WordPress core to 7.0.3 - #445

Merged
oxyc merged 1 commit into
masterfrom
security/wp-core-2026-08-06
Aug 6, 2026
Merged

security: update WordPress core to 7.0.3#445
oxyc merged 1 commit into
masterfrom
security/wp-core-2026-08-06

Conversation

@oxyc

@oxyc oxyc commented Aug 6, 2026

Copy link
Copy Markdown
Member

Bumps roots/wordpress / roots/wordpress-no-content 7.0 → 7.0.3.

WordPress 7.0.3 (released 2026-08-06) is a security release fixing 12 vulnerabilities; the fixes were backported to every supported branch, and 7.0.3 is the patched release for this site's branch. The headline issue:

  • Pre-auth reflected XSS on the login screen, with potential to lead to PHP code execution — CVE-2026-64638 / GHSA-52p2-r8wf-jcrf, CVSS 8.9 (High), CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. Affects all WordPress 4.7.0–7.0.2.

The remaining issues (4× Contributor+ stored XSS, multisite privilege escalation, SSRF in URL validation, Author+ CSS injection, two info-disclosure issues, post slug enumeration, email confirmation bypass) all require at least a contributor account or are lower impact.

Why this is a manual PR: the nightly vulnerability scan will not catch this yet — no advisory for WordPress core has been published to the Packagist / wpsecadv databases that composer audit reads, so the scan currently reports clean.

Stays within this repo's existing composer.json constraint — lock-only change, no minor/major jump.

🤖 Generated with Claude Code

WordPress 7.0.3 is a security release fixing vulnerabilities disclosed on
2026-08-06, including a pre-auth reflected XSS on the login screen with
potential to lead to PHP code execution (CVE-2026-64638,
GHSA-52p2-r8wf-jcrf, CVSS 8.9 High).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@oxyc
oxyc merged commit 70ac5b0 into master Aug 6, 2026
@oxyc
oxyc deleted the security/wp-core-2026-08-06 branch August 6, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant