Technology newsroom
Urgent! WordPress 7.0.4 Releases Critical Security Patch; Synology and UGREEN NAS Users Should Update Immediately
WordPress 7.0.4 has released an urgent security update to close a critical RCE vulnerability. Synology and UGREEN NAS users must update manually or via Docker, as the update is not yet available in the Package Center.
π Key Takeaways:
- WordPress 7.0.4 has been released to fix a critical Remote Code Execution (RCE) vulnerability affecting versions 3.7 through 7.0.
- Synology and UGREEN NAS users cannot update via the Package Center yet; manual updates or Docker installations are the only options.
- It is strongly recommended to update your website immediately to prevent attacks via malicious file uploads.
On August 12, 2026, WordPress officially announced the release of version 7.0.4, a minor update focused on bug fixes and, most importantly, closing critical security vulnerabilities. All users should update as soon as possible.
π¨ Security Vulnerability Addressed
This update targets a critical Remote Code Execution (RCE) vulnerability that allows malicious actors with Author-level privileges or higher to upload harmful files to gain control over websites, especially those using Imagick and Ghostscript. This issue affects all WordPress versions from 3.7 up to 7.0, making an update extremely urgent.
βοΈ Recommendations for Synology and UGREEN NAS Users
For those hosting WordPress websites on Synology or UGREEN NAS, please be aware that version 7.0.4 is not immediately available for download via the Package Center. Therefore, you will need to perform a manual update or use a Docker installation method, which is recommended for its flexibility and enhanced security.
β¨ Enhance Your Website with the Latest Technology
Installing WordPress via Docker, following recommendations from experts like mariushosting, not only ensures you use the latest WordPress version but also provides a modern and highly secure environment. This includes PHP 8.5.9, MariaDB 11.8 LTS, Redis for performance enhancement, and Apache 2.4.68, ensuring your website operates at full efficiency and remains secure from threats in 2026. The next major version, WordPress 7.1, is scheduled for release in late August 2026.
π¬ For those hosting WordPress on a NAS, how do you typically update? Do you update manually, via Docker, or wait for the Package Center? Share your methods!