Hot on the heels of WordPress version 7.0.1 released just a week ago, version 7.0.2 addresses one moderate and one severe security vulnerabilities. These are net new issues, and do not appear to be connected to the recent release of version 7.0.1.
The SQL-injection issue affected WordPress versions going back to 6.8, while the critical combined attack affected versions going back to 6.9. That is why WordPress simultaneously released patched versions 6.8.6, 6.9.5, and 7.0.2.
The unusually fast release was therefore caused by the disclosure and coordinated repair of pre-existing vulnerabilities—not by a routine bug discovered in the 7.0.1 update. The WordPress team considered the risk serious enough to enable forced automatic background updates for affected installations. Updating to 7.0.2 promptly is strongly advisable even when a firewall or security plugin is installed.