A critical security vulnerability, CVE-2026-63030, was recently disclosed in WordPress core. The vulnerability affects WordPress 6.9.x versions before 6.9.5 and WordPress 7.0.x versions before 7.0.2. Under certain conditions, it could allow an unauthenticated attacker to perform SQL injection and potentially achieve remote code execution.
This weekend, we tested the latest version of Pressbooks with WordPress 6.9.5 and confirmed that they are compatible. Pressbooks hosted services are already running WordPress 6.9.5.
We have also updated the Pressbooks README.md on GitHub to reflect WordPress 6.9.5 as the currently recommended version. The previous recommendation was outdated, and we apologize for any confusion or concern this may have caused.
Administrators of self-hosted Pressbooks installations should upgrade WordPress to version 6.9.5 or another version containing the security fix as soon as possible.
We are continuing to test Pressbooks with WordPress 7.0.2 and expect to support it in an upcoming release.