WordPress released version 7.0.3 on 6 August 2026, a security release that fixes twelve vulnerabilities. The most serious is a pre-authentication reflected cross-site scripting flaw on the login screen, rated 8.9 out of 10 for severity, which the release notes say can be escalated to remote code execution. Search Engine Journal reported the release on 6 August 2026. Every WordPress site should be on 7.0.3 or later.
What WordPress patched in 7.0.3 on 6 August 2026
WordPress 7.0.3 fixes twelve vulnerabilities, according to Search Engine Journal's report on 6 August 2026. The headline flaw is a reflected XSS bug on the login screen that requires no authentication at all, which is why it carries an 8.9 High severity rating. The description states that through a specially crafted malicious third-party website hosted by an attacker, the flaw can be escalated to a remote code execution vulnerability. The attack does need social engineering and explicit interaction from the person being targeted.
The facts of the release as reported are below, which is the fastest way to check whether your site is exposed.
| Detail | What the release reports |
|---|---|
| Release | WordPress 7.0.3, published 6 August 2026 |
| Issues fixed | 12 vulnerabilities |
| Most serious flaw | Pre-auth reflected XSS on the login screen, rated 8.9/10 High, escalatable to RCE |
| Affected versions | All WordPress versions; the fix is backported to 4.7 and later |
| Conditions for attack | Requires social engineering and explicit user interaction |
Why a pre-authentication flaw on the login screen is different
Pre-authentication means an attacker needs no account and no password on the target site. The login screen is reachable on almost every WordPress install that has not been hardened, which puts the vulnerable surface on essentially every site running an unpatched version. That is what separates this from the usual plugin advisory, where an attacker needs at least a subscriber account first.
The mitigating detail, reported alongside it, is that exploitation is not automatic. The security vendor Patchstack published mitigation rules at disclosure and noted that the social engineering requirement makes mass exploitation unlikely. So the risk profile is a targeted attack against a specific site rather than a botnet sweeping the internet.
The other eleven fixes in WordPress 7.0.3
Search Engine Journal listed the remaining patched issues in the 6 August 2026 release, and they reach well beyond the login screen.
- Stored XSS in the Post Date, Post Content and emoji settings blocks
- Stored XSS in Quick Edit on sites with large numbers of users
- Server-side request forgery in URL validation, allowing requests to link-local IP ranges
- Privilege escalation on multisite networks that have user registration enabled
- An email confirmation bypass
- CSS injection through a safe CSS filter bypass
- Information disclosure in the Latest Comments block for password-protected posts
- Disclosure of notes in comment feeds, and post slug enumeration
If you run a multisite network with open registration, the privilege escalation fix is the one to prioritise, since it turns an ordinary signup into a route to higher access.
This is a security story, not a ranking story
Search Engine Journal does not report any ranking or search visibility effect from these vulnerabilities, and nothing in the release suggests that patching changes how a site performs in search. Anyone calling 7.0.3 a ranking update has invented that part.
The connection that is real is indirect. A compromised WordPress site tends to end up with injected spam pages and redirects that its owner never added, which damages trust with visitors and costs time to clean up. None of that is caused by this specific vulnerability, and no exploitation of it has been reported. The point is that site security and site performance share an owner, and the owner is usually the marketing team.
What this means for Thai marketers
The release applies to WordPress everywhere, so any WordPress site in Thailand is in scope, and the source does not single out any country. The practical question is whether automatic updates are actually running on your install. WordPress ships security patches through fast auto-updates, which means most sites will land on 7.0.3 without anyone doing anything.
The exception is the kind of site that gets built for brands: heavily customised themes, managed hosting with updates deliberately frozen, or a staging workflow where core updates are pushed manually after testing. Those are exactly the builds where auto-updates are off, and they are common in agency-delivered WordPress website projects. Check the version number in the admin dashboard, or ask whoever maintains the site to confirm in writing that it is on 7.0.3 or later. A site neglected long enough that nobody knows its update status usually has other problems, which a technical site audit will surface alongside the crawl and indexing issues that affect organic search performance.
Frequently asked questions about WordPress 7.0.3
Do I need to do anything if auto-updates are on?
Probably not, but verify rather than assume. WordPress auto-updates security releases quickly, so most sites are already on 7.0.3, and the version in your admin dashboard is the only reliable way to know.
Which WordPress versions are affected?
All of them, according to the release. The fix has been backported across supported branches to version 4.7 and later, so an older site on a maintained branch can still receive the patch.
Does this affect my Google rankings?
No, and the source does not report any ranking or search visibility effect. This is a security patch. The indirect risk is that a site compromised through any vulnerability can end up serving spam content that damages trust, but that is a separate scenario from this release.
Is anyone exploiting this vulnerability right now?
The source does not report any active exploitation. Patchstack published mitigation rules when the flaw was disclosed and said the social engineering requirement makes mass exploitation unlikely, which is not the same as saying a targeted attack is impossible.
Does this apply to WordPress sites in Thailand?
Yes, because the vulnerability is in WordPress core and has nothing to do with location. Search Engine Journal does not mention Thailand or any other market, since the affected code is the same everywhere.
The version check worth doing today
Twelve fixes, one of them reachable without a login on every unpatched install, and a patch already shipping automatically to most sites. The work is a version check, and the sites that need it most are the ones where somebody once had a good reason to turn automatic updates off. Relevant Audience can take a look if nobody is certain when your site was last updated.







