WordPress 7.0.4 is a security release and should be applied promptly. WordPress.org recommends updating sites immediately. Start by confirming a usable restore path, apply the normal core update, clear the cache layers that can hide a changed site, and verify public and business-critical workflows.
This checklist is for site owners, agencies, and hosting teams. It keeps the work controlled and defensible: plan the change, update through the normal WordPress or managed-host path, and document the verification. It does not include vulnerability testing or reproduction material.
What WordPress 7.0.4 changes
The official release announcement says WordPress 7.0.4 includes a security fix, tracked as CVE-2026-65640. WordPress identifies the affected condition as involving sites that use Imagick and Ghostscript, with authenticated author-level or higher access. That is a reason to patch promptly, review who has publishing access while the update is underway, and keep normal least-privilege controls in place.
Update the 7.0 branch to 7.0.4. The official advisory confirms that the fix is also backported to WordPress branches through 4.7. For another branch, use the latest compatible security release offered in the site's Dashboard or managed-host control panel instead of assuming that an older version has already received the fix. Only the most recent WordPress version is actively supported.
Sites that support automatic background updates may begin updating shortly. Automatic completion is not the end of the work: confirm the installed version, clear the cache layers that serve visitors, and verify the workflows that matter to the site.
Before the update: confirm a real restore path
Confirm that a current backup includes both WordPress files and the database, where it is stored, and who can restore it. For important sites, use the WordPress backup and restore-point checklist and the backup restore test guide before beginning.
Record the installed WordPress version, active theme, and any business-critical plugins or custom features. Keep this core security update focused: do not combine it with unrelated major plugin, theme, PHP, or hosting changes unless a confirmed compatibility requirement makes that necessary. Review active user accounts and role assignments as part of the normal access check.
Apply the WordPress 7.0.4 update
- Confirm the backup and restore point.
- Check the WordPress dashboard or managed-host control panel for the matching supported core release.
- Apply the normal WordPress core update and let it finish without starting a second update.
- Sign in again and confirm the installed version is WordPress 7.0.4, or the latest applicable security release for that branch.
- Clear the page, object, and CDN cache layers used by the site.
- Open the public site in a private browser window before calling the work complete.
For a portfolio of sites, start with the most exposed or business-critical sites, then use a representative site for compatibility checks before moving through the remaining low-risk group. The WordPress update-window guide can help teams assign checks and keep the change controlled.
Post-update verification checklist
- Open the home page, a key landing page, a recent post, and a contact page without a logged-in session.
- Confirm the WordPress dashboard reports the expected version.
- Open a representative editor screen and confirm blocks, templates, and media controls load normally.
- Submit a monitored test form where the site's normal process permits it.
- For a store, check product pages, cart behavior, checkout, account access, and transactional email.
- For membership, booking, donation, or learning sites, test one visitor journey and one staff workflow.
- Review error monitoring and the host error log for repeatable new failures.
- Check key pages for normal performance and search behavior after cache clearing.
Use the WordPress performance-after-updates guide for the public performance check. For canonical URLs, crawlability, sitemaps, and important search pages, use the WordPress SEO monitoring guide. Sites behind a CDN should also follow the WordPress CDN update checklist.
If something breaks after the update
Pause the next site in the batch, capture the time and visible symptom, and check the public page separately from the logged-in dashboard. Rule out a stale cache before changing code. If a theme, plugin, or custom integration is likely involved, use the documented restore point or a staging copy instead of trial-and-error changes on a customer-facing site.
If the site cannot be stabilized promptly, restore the known-good state, clear the relevant caches, and verify the public site before scheduling a compatibility review. The Fix I.T. Phill WordPress Support hub collects maintenance, recovery, migration, and hardening guidance.
WordPress 7.0.4 security update FAQ
Is WordPress 7.0.4 a security release?
Yes. WordPress describes 7.0.4 as a security release and recommends updating sites immediately.
Will the update happen automatically?
Sites that support automatic background updates may begin updating shortly. Verify the installed version and the site's important workflows even when the update was automatic.
What should an older WordPress branch do?
The official advisory confirms that WordPress security releases containing this fix are available for branches through 4.7. Install the current security release offered for the site, then verify its installed version and key workflows.
Where can I review the official release information?
See the WordPress 7.0.4 release announcement and the official WordPress update documentation.


