TL;DR
WordPress 7.1.1 landed as a maintenance and security release. It fixes 11 security issues in the popular CMS, including stored cross-site scripting. The WordPress security team urges site owners to update at once.
Track every WordPress CVE the moment it's exploited.
Get free email alertsWhy the WordPress 7.1.1 release matters
WordPress powers a large share of the web. A single flaw can therefore reach millions of sites. This WordPress security release closes 11 holes at the core level.
The team ships it as a short-cycle update. Alongside the fixes come 17 core bug fixes and 19 Block Editor bug fixes. Because it is a security release, the project recommends immediate action.
HwordwWordPress 7.1.1 security release patching 11 vulnerabilities including stored cross-site scripting and path traversal flawsow the flaws work
Several issues involve stored cross-site scripting (XSS). One sits in the wpautop() function and could let an unauthenticated visitor inject script, subject to comment approval. Another affects some themes that support custom headers.
Other fixes address access-control gaps. These include an authenticated path traversal in the REST templates controller and a Contributor-level arbitrary post overwrite. Notably, Anthropic reported both of those two issues. The update also blocks a crafted URL that could install and preview an inactive theme.
Affected versions
The flaws affect WordPress versions before 7.1.1. No CVE identifiers appear in the advisory. The WordPress team reports no active exploitation, and no public proof-of-concept has been confirmed.
Patch and mitigation steps
Update to WordPress 7.1.1 right away. You can install it from your dashboard under Updates. Sites with automatic background updates should apply this WordPress security release on their own. For full details, read the official WordPress 7.1.1 security release announcement. Finally, confirm the update completed and keep automatic updates enabled.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!