08/12/2026
WordPress 7.0.4 is out — and every site we manage is already on it.
This one's serious: it patches an authenticated remote code ex*****on flaw. In plain terms, a logged-in Author-level user on a vulnerable site could upload a crafted file and run their own code on the server. If your site allows contributor or author registration — membership sites, multi-author blogs, communities — that's your exposure. The fix reaches back nearly a decade of WordPress versions.
Here's the part worth sitting with: the flaw was found by an AI security firm (pwn.ai)—the second WordPress release in a row where AI surfaced a critical bug. The same models attackers can point at your site are now finding and weaponizing vulnerabilities in hours, not weeks. The old "we'll patch at the next maintenance window" approach was built for a slower world.
That's the whole point of managed care: your site is patched, monitored, and backed up before most people have even read the release notes.
👉 Book a free 30-minute strategy call — no pitch, no pressure. kingswooddigital.com