The latest security release for WordPress, 7.0.2, is available on Pantheon as of July 17, 2026.
Action required
Because this is a security update, we recommend upgrade to WordPress 7.0.2 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.
Highlights
This update resolves two security vulnerabilities that were reported via WordPress core's HackerOne reporting portal. Fixes in this release include:
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5 has been released with fixes for both and is also available from our WordPress upstream.
WordPress 6.8 is only affected by the first vulnerability. Version 6.8.6 has been released with the fix and is available from our WordPress upstream.
For more information on this release, please visit the HelpHub site.