WORDPRESS 7.1.1 is a maintenance and security release addressing 11 vulnerabilities in versions before 7.1.1. The fixes include several stored cross-site scripting (XSS) issues, including one in the `wpautop()` function that could allow an unauthenticated visitor to inject script, subject to comment approval. Another affects some themes supporting custom headers. The release also contains 17 core bug fixes and 19 Block Editor fixes.
Other security fixes address access-control problems, including an authenticated path-traversal flaw in the REST templates controller and a Contributor-level vulnerability that could enable arbitrary post overwriting. Anthropic reported both issues, according to the article. WordPress also blocked a crafted URL that could install and preview an inactive theme.
No CVE identifiers were listed, and the WordPress team reportedly said it had found no evidence of active exploitation or a confirmed public proof of concept.
Site owners are urged to update to WordPress 7.1.1 immediately through the dashboard’s Updates section. Websites using automatic background updates should receive the release automatically, but administrators should verify that the update completed successfully and keep automatic updates enabled.