WordPress 7.0.2 is now available as a security release. The update addresses one critical and one high-severity vulnerability. Because of the severity, vendor claims that the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.
The security team credits TF1T, dtro, and haongo for reporting a facilitated SQL injection issue. Another issue, reported by Adam Kues at Assetnote / Searchlight Cyber, involves a REST API batch-route confusion leading to Remote Code Execution (RCE).
Affected versions and backports:
- WordPress 6.9: Affected by both vulnerabilities. Version 6.9.5 has been released containing fixes.
- WordPress 6.8: Affected by the first vulnerability. Version 6.8.6 has been released containing a fix.
- WordPress 7.1 beta: Affected by both vulnerabilities. Version 7.1 beta2 has been released containing fixes.
- Prior to 6.8: Not affected.
To update manually, visit the WordPress Dashboard, navigate to Updates, and click Update Now. Alternatively, download the package directly from WordPress.org. Sites that support automatic background updates will begin the process automatically.
Refer to the official release notes for CVE references CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf and CVE-2026-63030 / GHSA-ff9f-jf42-662q.