TL;DR
WordPress released version 7.1.3 on October 6, 2026. The WordPress 7.1.3 security update addresses seven reported issues, including stored XSS, a second-order SQL injection and a denial-of-service bug. The project urges site owners to update right away.
Turn WordPress CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
WordPress powers a huge number of websites, so core flaws reach far. This is a WordPress security release, and the notes say plainly: “Because this is a security release, it is recommended that you update your sites immediately.”
So far, no exploitation in the wild or public proof-of-concept has been confirmed for any of these issues. WordPress has not assigned CVE numbers in its release notes.
How the Attacks Work
Injection and Scripting Flaws
Two bugs allow cross-site scripting. One is a stored XSS on the Comments admin page, “exploitable via pending comments.” Another affects Imgur embeds. Meanwhile, a second-order SQL injection sits in the WXR export feature.
Access and Disclosure Issues
One weakness lets users with the Author role make posts sticky. Another leaks comments on private and unpublished posts without authentication. In addition, forgeable parameters passed to the status hook can cause action name collisions.
Denial of Service
Finally, a DoS issue affects the WP_Http::make_absolute_url() method.
Who Reported Them
Credits go to Trail of Bits, Patchstack, the WordPress security team and outside researchers. Anthropic reported three of the seven issues.
Affected Versions
All WordPress versions before 7.1.3 are affected. As a courtesy, the fixes are also available in older affected branches. However, WordPress notes that “only the most recent version of WordPress is actively supported.”
Patch and Mitigation Steps
Install the WordPress 7.1.3 security update now through the dashboard or your host. Sites with automatic background updates should receive it on their own, but check to confirm. Full details appear in the WordPress 7.1.3 release notes.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!