Skip to main content

Pantheon release notes

Your destination for staying informed about our latest innovations and product updates.
Subscribe to RSS feed

WordPress
October 6, 2026

The latest security release for WordPress, 7.1.3, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.3 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has deployed a platform-wide mitigation (virtual patching via our routing network) against external abuse of the stored XSS on the Comments administration page, and is actively monitoring that rule. However, customers need to update their sites as soon as possible.

Highlights

This release resolves seven security vulnerabilities:

  • A stored XSS on the Comments administration page, exploitable via pending comments.
  • A DoS issue in the WP_Http::make_absolute_url() method.
  • A second-order SQL injection in WordPress WXR export.
  • A weakness allowing Author role users to sticky posts.
  • Unauthenticated disclosure of comments on private and unpublished posts.
  • Imgur embeds are vulnerable to XSS.
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision.

For full details, see the WordPress 7.1.3 release notes and WordPress documentation.

October 2, 2026

The 1.34.0 update is now available for the WordPress (composer managed) upstream. This update changes the default PHP version to 8.3, syncs the upstream with Roots Bedrock, and fixes a PHP warning. The Bedrock sync changes the Composer repository defaults, which can cause merge conflicts in your composer.json file.

Updates

  • Updates the default PHP version to 8.3 and changes the PHP requirement in composer.json to >=8.3. For more information about the PHP default change, see New default PHP version 8.3 for WordPress upstreams. (For more information see #204.)
  • Syncs the upstream with Bedrock. (For more information see #201.) This includes:
    • Changing the Composer repository from WPackagist (wpackagist.org) to WP Packages (repo.wp-packages.org). Package names for plugins and themes change from wpackagist-plugin/* and wpackagist-theme/* to wp-plugin/* and wp-theme/*.
    • Removing the roots/wp-password-bcrypt package from composer.json.
    • Setting WP_ENVIRONMENT_TYPE from WP_ENV when it is not already defined, and setting WP_DEVELOPMENT_MODE when it is configured.
    • Setting MYSQL_CLIENT_FLAGS to use SSL when DB_SSL is set.

Bug fixes

  • Resolves a rtrim() warning in PHP 8.1 and later environments. (For more information see #189. Props @mattmacneil.)

For more details, refer to the WordPress (Composer Managed) changelog.

Action required

To benefit from these updates and ensure your site is using the most current version, apply the update to your WordPress (composer managed) site or custom upstream.

If your composer.json file requires plugins or themes using wpackagist-plugin/* or wpackagist-theme/* package names, or has custom entries in repositories, applying this update can cause merge conflicts in that file. When you resolve the conflicts, keep your custom requirements and update the package names to the new wp-plugin/* and wp-theme/* names, or keep the WPackagist repository entry.

For assistance with managing merge conflicts, refer to our documentation on auto-resolving via the dashboard or manually resolving via the command line.

October 2, 2026

Pantheon has updated the default PHP version for the WordPress and WordPress (composer managed) upstreams to PHP 8.3, replacing the previous default of PHP 8.2.

New sites created from these upstreams use PHP 8.3. Existing sites that do not set php_version in their own pantheon.yml move to PHP 8.3 when they apply this upstream update.

Action required

Test the update before you deploy it to the Live environment. Apply it in Dev or a Multidev environment, confirm your plugins and theme work on PHP 8.3, then promote it.

If your site needs to stay on PHP 8.2, pin the version by setting php_version: 8.2 in your site's pantheon.yml before you apply the update. For steps, see Manage PHP Versions.

If you maintain a custom upstream, this change is not reflected in your pantheon.upstream.yml unless you update your fork from Pantheon's upstream.

September 30, 2026

Version 1.4.1 of the Pantheon Content Publisher WordPress plugin is now available.

What's new?

Improved how Smart Components are placed in your posts and pages, including in the Content Publisher preview. #261

Update to 1.4.1 from the WordPress dashboard under Plugins > Installed Plugins, or download it from the WordPress Plugin Repository.

For more details, see the plugin changelog.

September 22, 2026

The latest security release for WordPress, 7.1.2, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.2 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of this vulnerability (CVE-2026-87902), and is actively monitoring those rules. However, customers need to update their sites as soon as possible.

Highlights

This release resolves one critical severity vulnerability (CVE-2026-87902) that does not require authentication to exploit. Under certain server and theme conditions, an unauthenticated attacker can cause page template resolution to include a chosen readable local PHP file outside the active theme directories, which could potentially lead to remote code execution.

For full details, see the WordPress 7.1.2 release notes and WordPress documentation.

September 18, 2026

The latest security release for WordPress, 7.1.1, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.1 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of some of these vulnerabilities, and are actively monitoring those rules. This includes an unauthenticated stored cross-site scripting vulnerability (CVE-2026-93485), reported through Patchstack's Vulnerability Disclosure Program, which was already covered by these mitigations ahead of the release. However, customers need to update their sites as soon as possible.

Highlights

This release resolves 11 security vulnerabilities, most requiring an authenticated role (Contributor or above) to exploit. WordPress has not assigned CVE identifiers to these issues.

For full details, see the WordPress 7.1.1 release notes and WordPress documentation.

September 18, 2026

Version 1.4.0 of the Pantheon Content Publisher WordPress plugin is now available.

What's new?

New Feature: Smart Components ** You can now embed videos and interactive smart components directly into your posts and pages using the updated Google Docs add-on. #206

Update to 1.4.0 from the WordPress dashboard under Plugins > Installed Plugins, or download it from the WordPress Plugin Repository.

For more details, see the plugin changelog.

August 19, 2026

The latest version of WordPress, 7.1, is available on Pantheon as of August 19, 2026.

Action required

Upgrade to WordPress 7.1 right from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Highlights

  • Collaboration with Notes — Inline notes with @mentions and rich text formatting, plus suggestion mode and emoji reactions for asynchronous feedback.
  • Expanded styling controls — Style blocks across screen sizes and style interactive states without writing custom CSS.
  • Media improvements — A free-form image cropper, support for more image formats, and more resilient client-side media handling.
  • New blocks — A Playlist block for collections of audio files with optional waveform visualization, and a Tabs block for organizing content into clickable panels.
  • Site identity in the Site Editor — Title, tagline, and site icon now live in their own labeled section.
  • Accessibility — A new accessible tooltips API, more predictable screen reader behavior, and improved labeling throughout the admin.
  • ...and more

For full details about WordPress 7.1, see the release notes or the WordPress 7.1 Field Guide.