WordPress 7.0.3 was released today (a couple of hours ago). This is an important security release containing fixes for 12 vulnerabilities, so site owners are strongly advised to update immediately.
The most serious issues include a pre-auth reflected XSS vulnerability on the login screen that could potentially lead to PHP code execution, an SSRF vulnerability allowing requests to link-local addresses, and a multisite privilege-escalation issue affecting networks with user registration enabled.
The release also fixes several stored XSS vulnerabilities available to Contributor or Author-level users, a CSS injection issue, an email-confirmation bypass, post slug enumeration, and multiple cases where protected information could be exposed through blocks or comment feeds.
Security fixes were also backported to older WordPress branches. WordPress 6.9 received version 6.9.6, while affected versions down to WordPress 4.7 received their own security updates. WordPress 4.6 and earlier no longer receive security fixes.
You can update directly from Dashboard → Updates or download the latest release from WordPress.org.
After updating, clear your site and server caches and quickly verify the login screen, editor, Quick Edit, and multisite registration if those features are in use. No WordPress packages were revised in this release.
If you manage client websites or have automatic core updates disabled, now is a good time to check every installation manually.