securityonline.info 6 Oct 2026, 17:37 UTC

WordPress 7.1.3 Fixes Seven Security Flaws, Urgent Update Advised

WordPress 7.1.3 Fixes Seven Security Flaws, Urgent Update Advised

WORDPRESS has released version 7.1.3 on 6 October 2026 to fix seven reported security issues, including a stored cross-site scripting (XSS) flaw, a second-order SQL injection and a denial-of-service (DoS) bug. The update is framed as a security release and site operators are urged to update immediately. WordPress notes that all versions prior to 7.1.3 are affected, with fixes also backported to older affected branches, though only the most recent WordPress version remains actively supported.

Details supplied by the article describe multiple vulnerability classes: two XSS flaws (one on the Comments admin page exploited via pending comments, and another affecting Imgur embeds), a second-order SQL injection in the WXR export feature, a privilege/visibility weakness that lets Authors make posts sticky, a comment disclosure issue on private and unpublished posts without authentication, forgeable parameters on a status hook causing potential action name collisions, and a DoS flaw in the WP_Http::make_absolute_url() method.

The article attributes discovery to researchers from Trail of Bits, Patchstack, the WordPress security team and Anthropic, though it notes WordPress did not publish CVE numbers in the release notes.

Practical response advised is to install WordPress 7.1.3 immediately via the dashboard or hosting provider, with automatic updates expected to apply unless disabled. The article also clarifies that, at present, there is no confirmed exploitation in the wild or public PoCs for these issues. No CVEs are assigned in WordPress’s notes.

View full article

Article by CyberSIXT