Wordpress 7.x — End of Life
Active Actively exploitedWordpress 7.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 7.0 | May 20, 2026 | — | No | 7.0.2 | Active |
CVEs affecting Wordpress 7.x (2)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-63030 | CRITICAL | 9.8 | 97.92% | KEV | 7.0 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which… | Jul 17, 2026 |
| CVE-2026-60137 | MEDIUM | 5.9 | 77.97% | KEV | 7.0 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p… | Jul 17, 2026 |
Frequently asked questions
Is Wordpress 7 end of life?
No. Wordpress 7.x is still supported. It continues to receive security patches and bug fixes.
What CVEs affect Wordpress 7?
There are 2 CVEs tracked for Wordpress 7.x, including 1 critical severity issue and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Wordpress 7 version?
The latest Wordpress 7.x patch release is 7.0.2, released on July 17, 2026. Always run the latest patch to benefit from all security fixes.
When was Wordpress 7 first released?
Wordpress 7.0 was initially released on May 20, 2026. See the full version timeline in the table above.
Is it safe to run Wordpress 7 in production?
Wordpress 7 is still supported and safe for production use. Ensure you are running the latest patch version (7.0.2) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
