NEWS · AUGUST 7, 2026 · WEB SECURITY

WordPress 7.0.3 is out: update your site now over the login screen flaw

WordPress shipped the 7.0.3 security release on August 6, 2026 and recommended updating sites without delay. The release closes 12 vulnerabilities. The one that stands out is a reflected XSS on the login screen that requires no authentication and carries the potential to lead to PHP code execution. The fixes were carried back into older branches as well.

01 · WHAT HAPPENED?

One security release, 12 vulnerabilities

WordPress 7.0.3 was released on August 6, 2026. The official release note states that this is a security release and recommends updating sites immediately. It also notes that sites which support automatic background updates will begin updating shortly.

Per the list in the version documentation, the closed issues fall into these categories: several stored cross site scripting (XSS) problems, a pre-auth reflected XSS on the login screen, a server side request forgery (SSRF), a privilege escalation on multisite networks, a CSS injection, a bypass of the email confirmation flow, and a few information disclosure issues.

Search Engine Journal reported on August 7, 2026 that the login screen issue carries a high CVSS rating of 8.9. The release note describes it as a flaw that can be triggered before authentication and has the potential to lead to PHP code execution.

02 · THE DETAILS

Which flaw sits where

The official documentation lists the issues one by one. Stored XSS problems that can be triggered by users with contributor level access or above sit in the Post Date block, the Post Content block, in posts via the emoji settings element, and in Quick Edit on sites with a large number of users. An information disclosure in the Latest Comments block exposed comments on password protected posts.

A CSS injection triggerable at author level or above comes from a bypass of the safe CSS attribute filter. On multisite networks with user registration enabled, a privilege escalation allowed a user to create a new site. The SSRF in URL validation allowed requests to link-local address ranges. The list also includes the email address confirmation bypass, a disclosure of notes in comment feeds, and an enumeration of post slugs.

The backport table shows the scope. WordPress 6.9 is affected by 11 of the 12 vulnerabilities. Branches from 6.8 down to 5.8 are affected by 8, and branches from 5.7 down to 4.7 by 7, with patch releases published for all of them. WordPress 4.6 and earlier no longer receive security updates.

The documentation also reminds readers that only the most recent version of WordPress is actively supported. The backport to older branches is a courtesy, and the durable answer is staying on the current branch.

03 · WHY IT MATTERS

Pre-auth means everyone

Most of the issues on this list carry a precondition: the attacker needs an account on the site. Problems that require contributor or author access form a limited surface outside multi author publications and sites that accept registrations.

The login screen flaw sits in a different category. Being triggerable before authentication means it can be aimed at visitors who hold no account at all. The release note mentioning the potential for PHP code execution raises the stakes further. Put those two together and leaving the update to next week stops being a reasonable choice. This assessment is ours.

The second point is timing. The moment a security release ships, the list of what was closed becomes public too. A patch is also a map. For sites that stay unpatched, risk does not fall after the release, it rises.

The third is the automatic update question. Background updates for minor releases run by default, but a hosting provider, a security plugin or a setting in the configuration file may have switched them off. So the sentence "automatic updates are on anyway" is not a substitute for verification.

04 · TURKEY

What it means for businesses in Türkiye

The assessment below does not appear in the sources, it is our reading. The sources carry no Türkiye specific breakdown or local note.

A large share of corporate sites for small and midsize businesses in Türkiye run on WordPress. Most of them were built once, handed over, and have stood for years without any maintenance relationship. That is exactly where the problem sits: when a security release ships and nobody is watching, nobody verifies that the update happened either.

Here is a three minute check for today. First, the version: open Dashboard and then Updates in the admin panel and confirm the version reads 7.0.3, or the new patch release of whichever branch you run. Second, the scope: if you operate a multisite network with user registration enabled, the privilege escalation item concerns you directly. Third, the user list: if contributor or author accounts belonging to people who no longer work with you are still active, the precondition for several issues on this list is already met.

One more reminder. This release covers WordPress core; plugins and themes are a separate surface. Updating core is necessary, but not sufficient on its own. That last sentence is our comment.

The UNALSOFT take

Days like this are precisely why we treat maintenance as its own line item for the sites we deliver in web design. Once a site goes live it is not a frozen document, it is running software: core, plugins and server keep receiving updates. Our preference is that the business does not have to track that calendar alone. Backup before the update, a functional check after it, and a record of the version. Today's task is short, open the panel and verify the version. Left until tomorrow, the task can get much longer.

Who is tracking your site's version?

Let's check the maintenance status of your current site together.

Message on WhatsApp