The WordPress development team has released WordPress 7.0.2, a security update that fixes two serious vulnerabilities affecting recent versions of the content management system. Website administrators are strongly encouraged to update their installations as soon as possible.
Due to the severity of the issues, the WordPress.org team has enabled automatic forced updates for affected versions through the auto-update system. Websites with background updates enabled should receive the update automatically.
WordPress 7.0.2 addresses one critical and one high-severity security vulnerability:
- A facilitated SQL injection vulnerability reported by security researchers TF1T, dtro, and haongo.
- A REST API batch-route confusion and SQL injection vulnerability that could lead to Remote Code Execution (RCE), discovered by Adam Kues of Assetnote / Searchlight Cyber.
Website owners who do not use automatic updates can install the new version manually by visiting the Updates section in the WordPress Dashboard and selecting Update Now, or by downloading WordPress 7.0.2 from the official WordPress website.
Security fixes have also been released for other supported branches:
- WordPress 6.9.5 fixes both vulnerabilities.
- WordPress 6.8.6 fixes the SQL injection vulnerability.
- WordPress 7.1 Beta 2 includes fixes for both security issues.
According to the WordPress security team, versions earlier than WordPress 6.8 are not affected.
The vulnerabilities are tracked under the following identifiers:
- CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf
- CVE-2026-63030 / GHSA-ff9f-jf42-662q
Website administrators are advised to ensure that WordPress core, themes, and plugins are kept up to date to reduce the risk of exploitation and maintain a secure website.








