The latest security release for WordPress, 7.0.3, is available on Pantheon.
Action required
Because this is a security update, we recommend all users upgrade to WordPress 7.0.3 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.
Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of the vulnerability, and are actively monitoring those rules. However, customers need to update their sites as soon as possible.
Highlights
This update resolves a number of security vulnerabilities, including:
- A pre-authentication reflected XSS attack that can lead to remote code execution
- Several other XSS issues that require an authenticated user
The RCE vulnerability is serious, but unlike wp2shell it requires specific targeting of a user to be effective. However, it is present on all versions of WordPress going back to 4.7. We will provide a list of backport patches shortly for customers on older branches of WordPress.
For more information on this release, please see the WordPress documentation.