NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1103 most downloaded on Packagist
WordPress is open source software you can use to create a beautiful website, blog, or app.
Last release 6 months ago
22 Mar 2026
Ships unpredictably
gaps range from 8 days to 2.1 years
Rarely documented
notes for 7 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
735 releases · first in 2018
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
One column per quarter.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
This security and maintenance release includes 17 bug fixes on Core , 19 bug fixes for the Block Editor , and 12 security fixes.
Sourced from WordPress.org Documentation.
This release was led by Adam Silverstein, Adrian Duffell, Andrei Draganescu and Aaron Jorbin.
This security and maintenance release includes 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 12 security fixes.
For a full list of bug fixes, please refer to the release candidate announcement.
This security and maintenance release features 16 bug fixes on Core, 21 bug fixes for the Block Editor, and 12 security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
Nothing published for this version
Nothing published for this version
Nothing published for this version
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Version notes available on WordPress.org Documentation .
Version notes available on WordPress.org Documentation.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Version notes available on WordPress.org Documentation .
Version notes available on WordPress.org Documentation.
The security team would like to thank the following people for responsibly reporting vulnerabilities , and allowing them to be fixed in this release:
Sourced from WordPress.org Documentation.
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →