WordPress 7.0.3 Security Release — Update Your Site Now

Sunday, August 9, 2026

On 6 August 2026, WordPress released version 7.0.3 as a security release addressing 12 vulnerabilities. If you run a self-managed WordPress site on a Hostify VPS or dedicated server, please update as soon as possible.

What Was Fixed

The most serious issue is a pre-authentication reflected cross-site scripting (XSS) vulnerability on the login screen with the potential to lead to PHP code execution (CVE-2026-64638). The release also fixes stored XSS vulnerabilities, a privilege escalation issue on multisite networks with user registration enabled, a server-side request forgery (SSRF) issue in URL validation, and an information disclosure affecting comments on password-protected posts.

What Hostify Did

  • All Hostify-managed WordPress installations on shared and WordPress hosting plans are being updated to 7.0.3 automatically.
  • Server-level security rules remain in place to detect and block exploitation attempts.

What You Should Do

If you self-manage WordPress on a Hostify VPS or dedicated server, update to 7.0.3 now. Log into your dashboard, go to Dashboard > Updates, and click Update Now. You can also check that automatic background updates are enabled. Remember, only the most recent WordPress version is actively supported — staying current is your best protection.

As always, our support team is available 24/7. Open a ticket if you need help updating or verifying your site.

Chat on WhatsApp