WordPress 7.0.4 is out, and it fixes a serious security vulnerability that could let an attacker take over your site. Update now. The release addresses an “Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript.” In plain English: if your site allows authors to upload files and uses specific image-processing tools, a logged-in author could upload a malicious file that runs code on your server, potentially giving them full control. This is a critical flaw, and the WordPress team recommends updating immediately.

This matters because your website is your digital storefront. If an attacker exploits this, they could deface your site, steal customer data, or install malware that harms your visitors and your reputation. The fix is straightforward, but only if you act now.

What Happened: A Security Patch with Teeth

WordPress 7.0.4 is a security release, meaning it contains no new features—just a critical fix. The vulnerability was responsibly disclosed by pwn.ai, a security research team, and the WordPress security team moved quickly to patch it. The update is available via your dashboard or WordPress.org, and sites with automatic background updates will get it soon.

The key detail: the flaw affects sites using Imagick and Ghostscript, which are common image-processing libraries. If your site allows authors to upload images, you're at risk. Even if you don't think you use these tools, many plugins and themes do behind the scenes.

Does This Affect Your Business?

If you run a WordPress site—which powers over 40% of the web—this affects you. The vulnerability requires an authenticated author-level account, so not every site is immediately exploitable. But if you have multiple authors, guest bloggers, or any user with author privileges, your risk is real. Even single-author sites should update because attackers often find ways to escalate privileges or exploit other vectors.

Here's the strategic angle: this is a reminder that WordPress's popularity makes it a prime target. The team's response is solid, but the onus is on you to stay current. Only the latest version is actively supported, so running an older version means you're unprotected.

What This Means for Your Business

Your website is a business asset. A security breach can lead to lost revenue, damaged customer trust, and costly cleanup. Updating to 7.0.4 is a low-effort, high-impact action that closes a known hole. If you're on a managed WordPress host, they may handle updates for you, but verify. If you're self-managed, log in and click “Update Now” today.

Don't wait for automatic updates—they may take time, and every hour you're vulnerable is an hour an attacker could strike. The backport to older branches (4.7) is a courtesy, but it's not a reason to delay upgrading to the latest version.

Your Move: Update This Week

Go to your WordPress dashboard, click Updates, and install 7.0.4. If you have a staging site, test there first, but don't skip this. After updating, check your site for any issues. This is a 10-minute task that protects your business.




Source: WordPress News

FAQ

It patches a critical remote code execution flaw that could let an author-level user take over your site via a malicious file upload.

Log into your dashboard, go to Updates, and click 'Update Now.' Or download from WordPress.org and replace your files.