Wordpress 7.x — End of Life

Active Actively exploited
1 release in this series2 CVEs

Wordpress 7.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
7.0May 20, 2026No7.0.2Active

CVEs affecting Wordpress 7.x (2)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-63030CRITICAL9.897.92% KEV 7.0WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which…Jul 17, 2026
CVE-2026-60137MEDIUM5.977.97% KEV 7.0WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p…Jul 17, 2026

Frequently asked questions

Is Wordpress 7 end of life?

No. Wordpress 7.x is still supported. It continues to receive security patches and bug fixes.

What CVEs affect Wordpress 7?

There are 2 CVEs tracked for Wordpress 7.x, including 1 critical severity issue and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Wordpress 7 version?

The latest Wordpress 7.x patch release is 7.0.2, released on July 17, 2026. Always run the latest patch to benefit from all security fixes.

When was Wordpress 7 first released?

Wordpress 7.0 was initially released on May 20, 2026. See the full version timeline in the table above.

Is it safe to run Wordpress 7 in production?

Wordpress 7 is still supported and safe for production use. Ensure you are running the latest patch version (7.0.2) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA