Files
llm-wiki/raw/articles/wordpress-7-0-2-security-release-2026-07-17.md
2026-07-18 10:09:57 +09:00

48 lines
4.1 KiB
Markdown

---
source_url: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
ingested: 2026-07-17
sha256: c379ae5d3a0531defdd179235aa29850e6360e0d7751e40f02300460bee0df05
discovered_from:
platform: discord
channel_id: '1477793137064935675'
channel_name: tw
message_id: '1527765733579292813'
author_id: '1477793167486226708'
posted_at: 2026-07-17T19:55:35.400000000Z
message_excerpt: "WordPress 7.0.2 緊急セキュリティリリース"
score: 2
score_reason: "Security release with concrete CVE/GHSA references; useful as raw watchlist material, but not specific enough to update the AI/security wiki pages this run."
---
## WordPress 7.0.2 is now available.
The 7.0.2 security release addresses one critical and one high severity security issue.
Because this is a security release, **it is recommended that you update your sites immediately.** Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.
To manually update you can visit your WordPress Dashboard, click “Updates”, and then click “Update Now”, or you can [download WordPress 7.0.2 from WordPress.org](https://wordpress.org/wordpress-7.0.2.zip). On sites that support automatic background updates, the update process will begin automatically.
## Security updates included in this release
The security team would like to thank the following people for responsibly [reporting](https://hackerone.com/wordpress) vulnerabilities and allowing them to be fixed in this release:
- A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at [Assetnote / Searchlight Cyber](https://slcyber.io/)
For more information on this release, please visit the [HelpHub site](https://wordpress.org/documentation/wordpress-version/version-7-0-2/).
## Backports
- WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5 has been released containing fixes for both.
- WordPress 6.8 is only affected by the first vulnerability. Version 6.8.6 has been released containing a fix.
- The beta release of WordPress 7.1 is affected by both vulnerabilities. Version 7.1 beta2 has been released containing fixes for both.
- Versions of WordPress prior to 6.8 are not affected.
## CVE and GHSA references
- [`CVE-2026-60137` / `GHSA-fpp7-x2x2-2mjf`](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf)
- [`CVE-2026-63030` / `GHSA-ff9f-jf42-662q`](https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q)
## Thank you to these WordPress contributors
This release was led by [John Blackbourn](https://profiles.wordpress.org/johnbillion/) and [Barry Abrahamson](https://profiles.wordpress.org/barry/). In addition to the security researchers mentioned above, WordPress 7.0.2 would not have been possible without the significant contributions of the following people: [Aaron Jorbin](https://profiles.wordpress.org/jorbin), [Alex Concha](https://profiles.wordpress.org/xknown), [annezazu](https://profiles.wordpress.org/annezazu), [Barry](https://profiles.wordpress.org/Barry), [David Baumwald](https://profiles.wordpress.org/davidbaumwald), [Dominik Schilling](https://profiles.wordpress.org/ocean90), [Ehtisham Siddiqui](https://profiles.wordpress.org/ehtis), [Joe Dolson](https://profiles.wordpress.org/joedolson), [Joe Hoyle](https://profiles.wordpress.org/joehoyle), [John Blackbourn](https://profiles.wordpress.org/johnbillion), [Jonathan Desrosiers](https://profiles.wordpress.org/desrosj), [Marius L. J.](https://profiles.wordpress.org/clorith), [Matt Mullenweg](https://profiles.wordpress.org/Matt), [Mohammad Jangda](https://profiles.wordpress.org/batmoo), [Peter Wilson](https://profiles.wordpress.org/peterwilsoncc), [Sergey Biryukov](https://profiles.wordpress.org/sergeybiryukov), [vortfu](https://profiles.wordpress.org/vortfu), [Weston Ruter](https://profiles.wordpress.org/westonruter), plus representatives from Altis, Automattic, Bluehost, Cloudflare, GoDaddy, Hostinger, and WP Engine.