VYPR
patchPublished Oct 6, 2026· 1 source

WordPress 7.1.3 Released with Seven Security Fixes

WordPress 7.1.3, a critical maintenance and security release, addresses seven vulnerabilities including stored XSS, DoS, and SQL injection flaws.

WordPress has rolled out version 7.1.3, a significant maintenance and security update that patches a total of seven vulnerabilities and four bug fixes. The core development team strongly advises all users to update their installations immediately due to the nature of the security issues addressed.

The update is available for download from WordPress.org, or users can initiate the update directly through their WordPress Dashboard by navigating to "Updates" and clicking "Update Now." For sites configured with automatic background updates, the process will commence automatically.

Among the critical security fixes are a stored cross-site scripting (XSS) vulnerability on the Comments administration page, which could be exploited via pending comments. Additionally, a denial-of-service (DoS) vulnerability was found in the WP_Http::make_absolute_url() method. Another significant flaw is a second-order SQL injection vulnerability present in the WordPress WXR export functionality.

Further security enhancements include the patching of a weakness that allowed users with the Author role to sticky posts, and an unauthenticated disclosure of comments on private or unpublished posts. The release also rectifies an XSS vulnerability affecting Imgur embeds and addresses an issue where forgeable parameters passed to the {status}_{type} hook could lead to action name collisions.

The WordPress security team extended its gratitude to the researchers and organizations who responsibly disclosed these vulnerabilities, allowing for their timely remediation. Notable contributors include Thomas Chauchefoin at Trail of Bits, Anthropic, Ananda Dhakal from Patchstack, and Zhengyu Liu, Jingcheng Yang, and Gavin Zhong.

This release was spearheaded by Jake Spurlock, with contributions from a broad array of WordPress core developers and community members, highlighting the collaborative effort behind maintaining the platform's security and stability. The asynchronous coordination among these individuals was crucial in delivering these fixes to a stable release.

As a courtesy, the security fixes are being backported to all eligible branches, including versions 4.7 and above, though users are reminded that only the most recent version of WordPress receives active support. The backporting process is currently underway and will be deployed as they become ready.

Users interested in contributing to WordPress core development are encouraged to visit Trac, select a ticket, and engage in discussions within the #core channel. Resources like the Core Contributor Handbook are available for those seeking guidance.

Synthesized by Vypr AI