VYPR
patchPublished Oct 7, 2026· 1 source

WordPress Core Patches Multiple Critical Vulnerabilities, Including XSS and SQL Injection

WordPress 7.1.3 addresses seven security issues, including stored XSS, SQL injection, and data disclosure flaws, urging immediate updates.

WordPress has released version 7.1.3, a critical security update that patches a total of seven vulnerabilities affecting its core software. The update, released on October 6, 2026, addresses a range of security weaknesses including cross-site scripting (XSS), SQL injection, and information disclosure flaws. While the release notes do not assign CVE identifiers or official severity ratings, the nature of the vulnerabilities necessitates immediate action from all WordPress users.

Among the patched issues is a stored XSS vulnerability on the Comments administration page. This flaw could allow attackers to inject malicious scripts that execute when administrators review pending comments, potentially leading to session hijacking or further compromise. The vulnerability was reported by Thomas Chauchefoin of Trail of Bits. The exact exploitation methods and payloads were not detailed in the disclosure.

A separate cross-site scripting vulnerability has been identified within WordPress's handling of Imgur embeds. This issue, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong, could be exploited when users embed content from Imgur, potentially leading to script execution in the context of the viewing user's browser. This highlights the importance of scrutinizing all embedded content, even from seemingly reputable sources.

Anthropic reported a second-order SQL injection vulnerability within the WXR export functionality of WordPress. While the specifics of the injection sequence and potential database impact are not fully elaborated, such vulnerabilities can sometimes lead to unauthorized data access or manipulation. Administrators are advised to be cautious with export operations until they are certain their systems are updated.

Further exacerbating security concerns, a vulnerability allows for the unauthenticated disclosure of comments associated with private and unpublished posts. Reported by Ananda Dhakal of Patchstack, this flaw means that sensitive information intended to remain private could be exposed to unauthorized parties. The disclosure indicates that comments are the primary exposed data, rather than entire posts.

In addition to these critical flaws, the update also rectifies an authorization issue where users with the 'Author' role could make posts sticky, a capability that should typically be restricted to editors or administrators. Separately, a denial-of-service (DoS) vulnerability was found in the WP_Http::make_absolute_url() method, also reported by Anthropic. While not directly leading to data compromise, DoS attacks can disrupt website availability and impact user experience.

WordPress strongly recommends that all users update to version 7.1.3 immediately. While fixes are also available for older, still-supported branches, the project emphasizes that only the latest version remains actively maintained. The security release impacts various components, including JavaScript in the administration area, export handling, REST API posts, HTTP processing, and embed functionalities. Users can update via their WordPress dashboard or by downloading the latest version from the official WordPress releases page.

Synthesized by Vypr AI