
Patch now
WordPress 7.0.2 addresses two serious security issues, including a flaw chain that could lead to remote code execution on affected installations.
At a glance
- WordPress says the release addresses one critical and one high-severity issue.
- Affected WordPress 7.0 sites should move to 7.0.2; supported 6.9 and 6.8 branches also received fixes where applicable.
- The two assigned identifiers are CVE-2026-60137 and CVE-2026-63030.
- WordPress enabled forced automatic updates for affected sites, but administrators should still confirm completion.
Copyright
© SecurityTalent.com — original summary and analysis






