Three WordPress Security Updates in Four Weeks: Why Website Care Matters

WordPress website owners have had a busy few weeks.

Between 17 July and 12 August 2026, WordPress released three consecutive security updates: WordPress 7.0.2, 7.0.3 and 7.0.4.

Each addressed security vulnerabilities in WordPress Core, and in each case WordPress recommended that website owners update promptly.

For businesses, there is a useful lesson here.

A WordPress website is not something that should be built, launched and then largely forgotten. Security updates can arrive at any time, sometimes only days apart, and somebody needs to know that they have been released, make sure they are installed and check that the website continues to work properly afterwards.

What has happened with WordPress updates recently?

The recent sequence started with WordPress 7.0.1 on 9 July 2026.

That was primarily a maintenance release, fixing 31 bugs across WordPress Core and the Block Editor.

Eight days later, however, WordPress 7.0.2 arrived as a security release.

It was followed by WordPress 7.0.3 on 6 August and WordPress 7.0.4 just six days later on 12 August.

The recent timeline therefore looks like this:

  • 9 July 2026 — WordPress 7.0.1: maintenance release containing 31 bug fixes.
  • 17 July 2026 — WordPress 7.0.2: security release addressing one critical and one high-severity security issue.
  • 6 August 2026 — WordPress 7.0.3: security release addressing 12 security issues.
  • 12 August 2026 — WordPress 7.0.4: security release addressing a remote code execution vulnerability affecting particular configurations.

Three security releases in less than four weeks is a good example of why ongoing WordPress website care matters.

WordPress 7.0.2 was particularly important

WordPress 7.0.2 addressed two significant vulnerabilities.

One involved SQL injection. The other involved a REST API issue combined with SQL injection that could lead to remote code execution.

Remote code execution is particularly serious because it can potentially allow an attacker to execute code on the affected system.

Because of the severity of the issues, the WordPress security team took the unusual step of enabling forced automatic updates for affected installations that supported the automatic update system.

I covered this vulnerability in more detail in my WP2Shell WordPress vulnerability article.

The important point for ordinary website owners is much simpler: when an update of this importance is released, leaving a vulnerable WordPress installation unattended is not a sensible option.

WordPress 7.0.3 followed with another 12 security fixes

Less than three weeks after WordPress 7.0.2, another security release arrived.

WordPress 7.0.3 addressed 12 separate security issues.

They included several cross-site scripting vulnerabilities as well as issues involving privilege escalation, information disclosure, post-slug enumeration, email confirmation and server-side request forgery.

Some of the vulnerabilities required an existing WordPress account with a particular level of access. Others had different prerequisites.

That distinction matters.

A security vulnerability does not automatically mean that every WordPress website can instantly be compromised by anybody on the internet. Different vulnerabilities have different conditions, levels of severity and practical risks.

But it also doesn’t mean they can simply be ignored.

The sensible response is to understand whether your website is affected and ensure the relevant security update is installed.

Then WordPress 7.0.4 arrived just six days later

On 12 August, WordPress released 7.0.4.

This update addressed another remote code execution vulnerability.

In this case, the vulnerability required an authenticated user with Author-level access or higher and affected sites using Imagick and Ghostscript. It involved a malicious file upload that could lead to remote code execution.

Those conditions are important because not every WordPress website was equally exposed.

However, WordPress still classified 7.0.4 as a security release and recommended updating immediately.

For a business owner, this demonstrates another problem with taking a casual approach to website maintenance.

You may have updated WordPress after hearing about 7.0.2.

You may even have checked again when 7.0.3 appeared.

Six days later, there was another security release to deal with.

Does this mean WordPress is insecure?

No.

The existence of security updates does not, by itself, mean that WordPress is unsafe.

WordPress is actively developed software used across a very large number of websites. Vulnerabilities are discovered, responsibly reported and fixed.

Being able to install those fixes is one of the advantages of using actively maintained software.

The bigger risk is running software for which a security fix exists without applying the fix.

This isn’t unique to WordPress. Operating systems, web browsers, phones, servers and business applications all receive security patches.

The UK’s National Cyber Security Centre has recently warned organisations to prepare for what it describes as a growing vulnerability patch wave, with businesses needing to be capable of applying security updates more quickly and more frequently.

Your website should be part of that thinking.

Automatic updates help, but they are not the whole answer

WordPress supports automatic background updates, and they can be extremely useful for getting important security fixes installed quickly.

But “automatic updates are enabled” shouldn’t be the entirety of a website maintenance strategy.

There are still questions worth answering:

  • Did the update actually complete?
  • Is WordPress Core fully up to date?
  • Are the plugins up to date as well?
  • Is the active theme maintained and current?
  • Did anything stop working after an update?
  • Are contact forms still submitting correctly?
  • Is the website still displaying properly?
  • Is there a recent backup if something does go wrong?
  • Would that backup actually be usable if the site needed to be restored?

Successful website care isn’t just about clicking an Update button.

It’s about knowing the current state of the website.

WordPress Core is only one part of the picture

The recent releases discussed here are WordPress Core updates.

A typical WordPress website also relies on a collection of plugins and a theme.

Those components have their own developers, release schedules, bug fixes and security updates.

This means a site can be running the latest version of WordPress Core while still having an outdated vulnerable plugin installed.

Equally, blindly updating everything without any form of backup or checking can create a different problem if an update introduces a compatibility issue.

Good WordPress maintenance therefore needs a balance:

Update promptly, but know what you are updating and verify the result.

What should WordPress website owners check now?

If you manage your own WordPress website, now is a good time to check it rather than assuming everything has updated automatically.

Start with the basics.

Check your WordPress version

Log in to WordPress and check whether WordPress Core reports an available update.

If you are running an affected older release, make sure the appropriate security update has been applied.

Check your plugins and theme

Look for outstanding updates.

An up-to-date WordPress Core installation does not compensate for a vulnerable plugin or theme.

Check your backups

Confirm that a recent backup actually exists.

Ideally, backups should not simply sit on the same hosting account as the website they are intended to protect.

Check the website after updating

Visit the important parts of the site.

Check key pages, navigation and any important functionality.

If your website generates enquiries, test the contact process rather than simply assuming it still works.

Check who has access

Review WordPress administrator and other privileged user accounts.

Remove old accounts that are no longer required and make sure users do not have greater permissions than they need.

Website care is an ongoing job

One of the easiest mistakes to make with a business website is assuming that because it is working today, everything is fine.

A website can look completely normal while running outdated software.

It can continue displaying pages while a security update is waiting to be installed.

It can even report that updates have completed without anybody checking whether important functionality still works afterwards.

The sequence of WordPress 7.0.2, 7.0.3 and 7.0.4 is a useful reminder that website maintenance isn’t an occasional housekeeping exercise.

Security releases don’t arrive according to your diary.

When an important vulnerability is discovered and fixed, the update arrives when it is ready.

Someone needs to be paying attention.

Not sure whether your WordPress website is being properly maintained?

If you’re unsure about the current state of your website, you can start with the Veloce IT Free Website Health Check for a quick look at several publicly visible technical signals.

If you already know that WordPress updates are being neglected, take a look at my WordPress Updates service.

I can help check the current state of your WordPress installation, deal with outstanding updates and identify whether your website needs more regular ongoing care.

Keeping WordPress secure isn’t about panicking every time a vulnerability is announced.

It’s about having a reliable process for noticing updates, applying them and making sure the website is still doing what your business needs it to do.