On 6 August 2026, WordPress released version 7.0.3 as a security release addressing 12 vulnerabilities. If you run a self-managed WordPress site on a Hostify VPS or dedicated server, please update as soon as possible.
What Was Fixed
The most serious issue is a pre-authentication reflected cross-site scripting (XSS) vulnerability on the login screen with the potential to lead to PHP code execution (CVE-2026-64638). The release also fixes stored XSS vulnerabilities, a privilege escalation issue on multisite networks with user registration enabled, a server-side request forgery (SSRF) issue in URL validation, and an information disclosure affecting comments on password-protected posts.
What Hostify Did
- All Hostify-managed WordPress installations on shared and WordPress hosting plans are being updated to 7.0.3 automatically.
- Server-level security rules remain in place to detect and block exploitation attempts.
What You Should Do
If you self-manage WordPress on a Hostify VPS or dedicated server, update to 7.0.3 now. Log into your dashboard, go to Dashboard > Updates, and click Update Now. You can also check that automatic background updates are enabled. Remember, only the most recent WordPress version is actively supported — staying current is your best protection.
As always, our support team is available 24/7. Open a ticket if you need help updating or verifying your site.