- WordPress.org blog: WordPress 7.0.3 release
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support automatic background updates will begin updating shortly. For more information, please visit the WordPress 7.0.3 HelpHub site. Security updates included in this release The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release: Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec) Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team Enumeration of post slugs reported by HDWSec Disclosure of notes in comment feeds reported by Elio Gubser Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic Bypass of the email address confirmation flow reported by 0ways A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters Backports As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready. WordPress 7.1 RC2 has also been released, containing all applicable fixes. CVE and GHSA references Details of the login screen XSS vulnerability can be found in the advisory: CVE-2026-64638 / GHSA-52p2-r8wf-jcrf. Thank you to these WordPress contributors This release was led by John Blackbourn. In addition to the security researchers mentioned above, WordPress 7.0.3 and its backports would not have been possible without the significant contributions of the following people:Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, adrianmoldovanwp, Aki Hamano, Alex Concha, Andrew Duthie, Andrew Serong, annezazu, Barry, Bernie Reiter, Daniel, Daniel Richards, David Biňovec, Dennis Snell, Ehtisham Siddiqui, Erwan Le Rousseau, Fabian Kaegy, fiocavallari, George Mamadashvili, gubser, Isabel Brison, Jarda Snajdr, Jb Audras, Jeremy Felt, Joe Dolson, Joe Hoyle, John Blackbourn, Jon Surrell, Jonathan Desrosiers, Khokan Sardar, Lance Willett, lucasbustamante, lucatume, Marco Ciampini, Marin Atanasov, Mohammad Jangda, Mukesh Panchal, Paul Kevan, Peter Wilson, ramonopoly, SergeyBiryukov, vortfu, Weston Ruter Join us for the launch of WordPress 7.1 at WordCamp US 2026, August 16–19.
- How to Price Your Online Course: One-Time vs Subscription vs Membership
One-time, subscription, or membership? Learn how to price your online course with real fee math, pricing psychology, and rules of thumb that work! The post How to Price Your Online Course: One-Time vs Subscription vs Membership appeared first on Themeisle Blog.
- Matt: Our Core Division
Inspired by Automatticians James Kemp and Dave Smith, I’ve been thinking a lot about how much of our discord in the design of WordPress stems from the differences of our two big tribes: Bloggers and Builders. Many of the OG developers of WordPress, including myself, tend more towards the blogging side. Writers, photographers, podcasters, journalists, the people for whom a reverse chronological stream on the homepage is the most obvious thing in the world. We link out a lot, love comments, social features and think a lot about the editor as a writing environment. Builders are the site shapers, webmasters, the agencies, the companies, the content managers that think in a more page-first rather than post-first way. Tagging? Blogroll? Date-based permalinks? Who needs them. Give me custom fields, rich templates, a site editor, to craft beautiful sturdy pages that will stand the test of time. A store with a catalog of items where what changes is the inventory and ratings, not the content. The Builders right now dominate our core development discourse, which makes sense. They hold a lot of the economic share with merchants and rich websites. They’re also more loyal. The Bloggers love their WordPress as the place they truly own and call home, but Bloggers have an account on every channel where there’s an audience, they syndicate out with an ephemerality mindset, because that reader/listener/follower connection is the spark that keeps their flame alive. A Builder would never be a digital sharecropper on someone else’s domain. Dave Smith has been doing some very interesting explorations of a simpler site editor, and you hear his Builder bias around 3:20 in how obvious a static homepage as default seems to him. The good news is we can coexist as we have at least since WordPress 1.5. We just need to give a little more love to the Blogger side, there’s so much cool stuff we could do in the Fediverse with RSS, ActivityPub, ATProto, blogrolls (link manager is still in wp-admin!), pingbacks…
- Open Channels FM: Creative Insights and Real Talk on Modern Marketing Challenges
Marketing's evolving fast. Creators and businesses must adapt as SEO and ads fade. Experimentation and multi-channel strategies are key to surviving now.
- How to Accept Custom Donation Amounts in WordPress with Stripe
Want visitors to set their own donation amount? Here's how to build a pay-what-you-want Stripe form in WordPress with WP Full Pay, fees included.











































































































































