WordPress 7: What Actually Changed in 7.0 and 7.1

by Francis Rozange | Oct 2, 2026 | WordPress

WordPress 7.0 was supposed to ship on April 9, 2026. It shipped on May 20, six weeks late. And the feature its beta announcement put first, real-time collaboration on the same post, was not in it. It is not in version 7.1 either, and it is not on the 7.2 roadmap.

That gap between announcement and delivery is the best reason to write this guide. A beta announcement does not tell you what will actually ship. Yet when you decide on an update or a development project, only the final release counts.

So we checked everything against official sources, namely the release announcements on wordpress.org, the field guides and the developer notes published on the contributors’ blog. What is not there is not in this inventory. At the time of writing, the current version is 7.1.2, released on September 22, 2026.

The calendar: from 7.0 to 7.1.2 in four months

WordPress 7.0, named “Armstrong” after Louis Armstrong, shipped on May 20, 2026. The planned date, April 9, was dropped at the end of March to finalize architecture choices tied to real-time collaboration. We come back to that in the real case.

Four maintenance and security releases of the 7.0 branch followed in July and August, including a forced security update on July 17. WordPress 7.1, “Mary Lou” after the pianist Mary Lou Williams, shipped on time on August 19, 2026. Versions 7.1.1 and 7.1.2 followed on September 17 and 22, the second for a single critical flaw; on the same days, the 7.0 branch got those fixes in 7.0.5 and 7.0.6. Version 7.2 is announced for early December 2026.

On October 1, 2026, according to wordpress.org statistics, 7.1 ran on about six sites in ten among those reporting their version. Sites still on PHP 7.2 or 7.3 are stuck on the 6.9 branch, which still receives security fixes as a courtesy, like every branch back to 4.7: only the latest version is officially supported.

What WordPress 7.0 changed

A new look for the admin

The admin adopts a new default color scheme, called Modern in the release notes and labeled “Default” in the profile; the old one remains available as “Fresh”. Users who had kept the default colors were switched automatically during the update, but anyone can go back to the old scheme from their profile.

Screen changes come with animated transitions, turned off when the operating system asks to reduce motion. The Command Palette gets a shortcut in the admin bar. A dedicated page for the font library appears, valid for every type of theme, and revision comparison becomes visual, with a slider in the editor.

One discreet security change is worth knowing: the Administrator and Editor roles can no longer be chosen as the default role for new users, under Settings, then General. If one of them was already selected, Site Health warns you. Our guide to WordPress user roles explains why that was dangerous.

The editor and layout

WordPress 7.0 lets you hide a block depending on the device, mobile, tablet or desktop. Careful: the hidden block stays in the page, simply hidden with CSS. Mobile menus can now be built with blocks and patterns, and each block can receive its own custom CSS.

Two new blocks arrive, Breadcrumbs and Icon. The gallery gains a lightbox slideshow, the Cover block now accepts an embedded video as its background, and the paragraph can be split into columns. Unsynced patterns are now edited as a whole, with only the content left editable: a change that may surprise themes that relied on free editing.

On the developer side, a block can now be declared entirely in PHP, without JavaScript, with a render callback. Our comparison of Gutenberg block plugins shows what these additions take away from block libraries.

The AI foundations, without the hype

The 7.0 announcement presents this release as the start of a new era, laying the foundation for AI across WordPress. In practice, core gets mostly plumbing and a settings screen, but no generation feature. An AI client, available to developers through the wp_ai_client_prompt() function, sends requests to a provider without depending on any particular one.

A new settings screen, dedicated to connectors, lets you plug in Anthropic, Google or OpenAI. But WordPress bundles no provider: you have to install the provider’s plugin and enter an API key. Keys stored in the database are not encrypted, only masked on screen; it is better to define them with a constant or an environment variable.

The features that generate titles, excerpts, images or alternative text come from a separate plugin, simply named AI. Installing WordPress 7.0 therefore writes nothing for you. Our guide to AI, the Abilities API and MCP covers these building blocks in detail.

These plugins have found their audience: in October 2026, the AI plugin has more than 50,000 active installs, as does each of the official provider plugins for Anthropic, Google and OpenAI.

The most structural building block, though, is the Abilities API, which arrived in PHP in WordPress 6.9: it lets a plugin declare what it can do, with its parameters and permissions. Version 7.0 adds a JavaScript counterpart, and 7.1 a single flag to expose an ability publicly, with the reminder that exposing is not authorizing: permission checks remain essential.

PHP 7.4 becomes the minimum

WordPress 7.0 drops PHP 7.2 and 7.3: the minimum version is now PHP 7.4, and the recommended version PHP 8.3 or higher. A site on PHP 7.2 or 7.3 does not receive the update to 7.0 and stays on the 6.9 branch. Since May 2026, WordPress also states that it fully supports PHP 8.5, without the old “beta” label.

Check your host’s PHP version before anything else; our guide to the right PHP version for WordPress explains how to change it without breaking things.

A glass frame nested inside another, with light flowing through both

What WordPress 7.1 changed

Styles for each screen size

Version 7.1 adds Tablet and Mobile states in Global Styles and on each block: a margin, a font size or a color can vary by screen, without CSS. The default breakpoints are 480 and 782 pixels, and a theme can redefine them in its theme.json file. Hover, focus and active styles also become adjustable, notably for the Button block.

The editor always in an iframe

A major change for developers: the post editor is now always displayed in an iframe, like the Site Editor, whatever the theme and blocks used, including with legacy meta boxes. In 7.0, this only happened under conditions. A script that manipulates the page document directly to act on the editor will no longer find anything: it must target the iframe’s document.

Images processed in the browser

Compression, resizing and thumbnail generation can now happen in the browser, thanks to a WebAssembly build of the libvips library. This mode, on by default, only works in recent Chrome and Edge, over HTTPS, on a powerful enough device; Firefox and Safari fall back to the server. An overly strict content security policy can block it. A filter turns it off.

add_filter( 'wp_client_side_media_processing_enabled', '__return_false' );

Notes, the admin bar and smaller things

Notes, introduced in 6.9 to comment on a block in the editor, gain rich text, mentions with notifications and notes on a text selection. Two new blocks arrive, Tabs and Playlist. The admin bar stays visible in every editor, and the media library switches to infinite scrolling by default, which each user can turn off in their profile.

For developers, an SVG icon API becomes public, accessible tooltip functions appear, and jQuery UI moves to version 1.14.2, with a few old functions removed.

Speculative loading, introduced in 6.8 to prefetch the likely next page, can now be configured with constants or environment variables, which makes life easier for hosts. On multisite, since 7.0, marking an account as spam no longer automatically marks its sites as spam.

The real case: the feature that never arrived

Real-time collaboration was meant to be WordPress 7.0’s showcase: several people editing the same post at the same time, as in an online word processor. Its removal is documented step by step on the official contributor blogs. It is the most instructive story of the 7 cycle.

The promise

In December 2025, planning for 7.0 put real-time collaboration first, while warning that it depended on servers more than usual. WordPress VIP customers had been testing it since October 2025, and 45 beta participants gave encouraging feedback on sites built with blocks.

On February 20, 2026, WordPress 7.0 Beta 1 presented it first, as an opt-in during the testing phase. Synchronization relied by default on regular requests to the server, in the absence of the persistent connections that not every host offers. A developer note specified that it turned itself off when legacy meta boxes were present, to avoid data loss.

The cracks

On March 19, the first release candidate was pushed back five days, partly because of collaboration performance. On March 31, Matias Ventura, the release lead, announced a delay of a few weeks to finalize architecture choices. The central question was how to store the changes: post metadata, a dedicated table, temporary data.

On April 2, Jonathan Desrosiers described a situation he called unprecedented: going back to beta after a release candidate. Commits for 7.1 were put on hold. On April 29, an urgent call asked hosts to test collaboration on their real configurations, including shared hosting with no object cache.

The decision

On May 8, 2026, Anne McCarthy announced that collaboration would not ship with 7.0. Matt Mullenweg did not consider the approach robust enough, citing code surface, race conditions, server load, memory and recurring bugs found through fuzz testing. The same day, test results from eight hosting environments were published.

Those tests showed that a dedicated table combined with temporary data would have been about 52% faster on average than the starting solution. But the decision was made: 7.0 shipped on May 20 without collaboration, and its announcement does not mention it at all. The feature remains available in the Gutenberg plugin, as an opt-in.

What came next

In June, at the core committers’ meeting at WordCamp Europe, the overwhelming majority of attendees approved the removal; some felt the story behind the feature had been poorly told. The 7.1 field guide confirmed it is not enabled in the final release. On September 18, 2026, a post by Chris Zarate announced a change of course: collaboration must be driven by the server.

The argument is concrete. An author inserts a script into a block, an administrator fixes a typo and saves: the script is saved with the administrator’s permissions. An automated script that reads at 9:00 and writes at 9:03 erases two editors’ work. The same day, the 7.2 roadmap deliberately left collaboration out, rather than announce it only to pull it later.

What the story teaches

A feature announced in beta is not a shipped feature: always check the final announcement and the field guide. Legacy meta boxes hold back modern editor features: plugins that depend on them are the first risk to audit. Finally, hosting matters: a feature that writes to the database often benefits greatly from a persistent object cache.

Other announcements that did not arrive

Collaboration is not the only feature announced then postponed. Hiding the Classic block from the inserter, announced in June 2026 for 7.1, was canceled in early July, and the plugin meant to bring it back was closed. The move to React 19 was pushed beyond 7.1.

Suggestion mode and reactions in notes became the goal for 7.2. “Guidelines”, editorial rules meant for AI, were not merged into 7.1. Conversely, the Playlist block, removed from the 7.0 field guide, arrived in 7.1, as did the mandatory iframe for the editor and in-browser image processing, which the 7.0 Beta 1 announcement had presented.

Security in the 7 cycle: five alerts in three months

The 7 cycle brought many security fixes, each announced and documented on wordpress.org. On July 17, 2026, version 7.0.2 fixed a chain of two flaws, a confusion in batched REST API requests and an SQL injection, that allowed remote code execution. Version 6.9 got both fixes in 6.9.5; 6.8, affected only by the SQL injection, got that fix alone in 6.8.6. The update was forced.

On August 6, 7.0.3 fixed twelve flaws, including a script injection on the login screen exploitable without an account and a privilege escalation on multisite, with fixes backported as far as version 4.7. On August 12, 7.0.4 closed a possible code execution for an author, through a malicious PostScript upload, on servers that use Imagick and Ghostscript.

On September 17, 7.1.1 brought eleven security fixes, and on September 22, 7.1.2 fixed a single critical flaw: under certain conditions, page template resolution could include a PHP file outside the themes and lead to code execution. The lesson is simple: every minor release counts, and that is exactly what automatic updates are for.

What developers must check

The breaking changes

  • The editor iframe: any script that targets the global document from the editor must go through the iframe’s document.
  • jQuery UI 1.14.2: a few old internal functions were removed.
  • Post lists: the row header moved from the checkbox to the title column, which can break CSS or JavaScript selectors.
  • Patterns: block attributes must be declared as content to stay editable in locked patterns.
  • Media: with in-browser processing, the image metadata generation hook can run twice; a plugin must handle that.
  • Content security policy: it must allow blob: workers for image processing.

The regressions fixed since

Version 7.1.1 fixed several 7.1 regressions, including one that could delete a removed user’s content on multisite without offering to reassign it, and another that served the native sitemap as a 404 error on sites with no published post. If you are still on 7.1.0, the update is not optional.

How to update to 7.1.2 safely

Back up and check the backup

The official documentation is blunt: back up the database regularly, and always before an update, then check that the backup exists and is usable. A backup that has never been restored is only a hypothesis, as our comparison of WordPress backup plugins points out.

Test on a copy

Before production, update a copy of the site: check the PHP version, your plugins’ “tested up to” value, the editor with your meta box plugins, an image upload and your content security policy. To test upcoming versions before release, the official WordPress Beta Tester plugin goes on a copy, never in production.

Keep minor updates automatic

The 7.0.2 update of July 17, which fixed a flaw chain rated critical, was forced by wordpress.org on affected sites. Turning off minor updates means giving up that safety net. Our WordPress maintenance checklist organizes that follow-up.

Configure automatic updates knowingly

The official documentation describes the available settings. The WP_AUTO_UPDATE_CORE constant accepts true for every release, 'minor' for minor releases only, or false. Turning off the whole update system is possible, but strongly discouraged by the documentation itself.

Finer filters, for plugins, themes or major releases, belong in a must-use plugin, a file in the mu-plugins folder that is always loaded, and never directly in wp-config.php. Since version 5.6, a fresh install also receives major updates automatically: on a sensitive site, prefer minor ones only and schedule major ones after a test.

Check the files after a command-line install

Two days after 7.0 shipped, a user reported that the stable WP-CLI wp core download command produced a broken install: some file paths that were too long, introduced with the AI client, were truncated on extraction, with no error message. The fix only exists in WP-CLI’s development build. After any install, run this check, covered in our selection of WP-CLI commands.

wp core verify-checksums

Summary table

Feature Version Status What to do
PHP 7.4 minimum 7.0 Shipped Check PHP, aim for 8.3
AI client and connectors 7.0 Shipped, no provider Keys via constant rather than database
New admin 7.0 Shipped Warn your users
Block visibility by device 7.0 Shipped Do not rely on it to lighten pages
Per-screen styles 7.1 Shipped Review custom CSS
Editor always in an iframe 7.1 Shipped Test meta box plugins
Images processed in the browser 7.1 Shipped, Chromium only Check your security policy
Real-time collaboration Announced for 7.0 Pulled, not on the 7.2 roadmap Do not wait for it
Hiding the Classic block Announced for 7.1 Canceled Nothing
React 19 Announced for 7.1 Pushed beyond 7.1, unlikely in 7.2 Test with Gutenberg

Frequently asked questions

Is real-time collaboration in WordPress 7?

No. It was pulled from 7.0 on May 8, 2026, is not enabled in 7.1 and is not on the 7.2 roadmap. It only exists in the Gutenberg plugin, as an opt-in.

Do I need PHP 8 for WordPress 7?

No. The minimum is PHP 7.4, the recommendation PHP 8.3 or higher. A site on PHP 7.2 or 7.3 stays on the 6.9 branch.

Does WordPress 7 write content with AI?

Not on its own. Core provides the plumbing; generation features come from a separate plugin, along with a provider plugin and an API key from that provider.

Should I wait before moving to 7.1?

No, as long as you go straight to 7.1.2, which fixes the known regressions and flaws. Test on a copy first if you use old plugins or a strict content security policy.

Why do my image uploads behave differently in Firefox?

Because in-browser image processing only works in recent Chrome and Edge. In Firefox and Safari, WordPress processes images on the server, as before.

Can I keep the old admin colors?

Yes. The old color scheme remains available under the name “Fresh”, in each user’s profile.

Conclusion

WordPress 7 is not the revolution its announcements suggested, but a series of solid changes: a refreshed admin, a more consistent editor, per-screen styles, images processed in the browser, and the foundations of an AI that still has to be plugged in. PHP 7.4 becomes the minimum, and the iframed editor forces old plugins to catch up.

The story of real-time collaboration recalls the golden rule: only the final release counts. Move to 7.1.2 after a verified backup and a test on a copy, keep minor updates automatic, and build nothing on a feature that is only announced.

Sources


LaFactory designs, builds and maintains WordPress and WooCommerce sites, and develops its own plugins. Talk to us about your WordPress project.

Francis Rozange

Former section editor at Libération, he runs LaFactory, an international web agency since 1996.

Cart