August 12, 2026
The latest security release for WordPress, 7.0.4, is available on Pantheon.
Action required
Because this is a security update, we recommend all users upgrade to WordPress 7.0.4 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.
Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of the vulnerability, and are actively monitoring those rules. However, customers need to update their sites as soon as possible.
Highlights
This update resolves a security vulnerability:
- An authenticated Author+ remote code execution via malicious file upload (CVE-2026-65640).
For more information on this release, please see the WordPress documentation.