WordPress 7.1.3 Fixes Multiple Critical Vulnerabilities

WordPress published version 7.1.3 on October 6, 2026, to address a number of serious security vulnerabilities, including cross-site scripting (XSS), SQL injection, data disclosure, and authorization flaws. The update covers both the newest release and older supported branches—site operators are urged to upgrade immediately. Only the latest release remains actively supported.

While the release notes list seven distinct security issues, they also call out “one security fix” in the summary. Notably, no CVE identifiers, severity rankings, or proof of active exploitation were included, meaning “critical” is not being used as an official classification for each flaw.

Among the most concerning risks is a stored XSS vulnerability in the Comments administration interface. Specifically, when reviewing pending comments, administrators may be exposed to malicious content. A separate XSS issue affects images embedded via Imgur—both cases could allow attackers to inject scripts into displayed content.

Another vulnerability enables second-order SQL injection through the WXR export feature. In some workflows involving export, unsafe data processing could allow attackers with partial access to escalate their ability to run SQL commands. Also addressed is an information disclosure bug that allows unauthenticated users to view comments linked to private or unpublished posts—data that normally should remain hidden.

Privilege escalation is also in focus: users with the “Author” role can now no longer make posts sticky—this behavior was previously improperly allowed and is considered an authorization issue. A separate flaw in the {status}_{type} hook parameters was discovered by the core security team—though its broader implications remain vague.

Finally, WordPress patched a denial-of-service gap found in the WP_Http::make_absolute_url() function. While included in the release, no request patterns or performance metrics were provided—so it’s unclear how easy it is to trigger.

Administrators can perform the update from the Dashboard under “Updates” or download it directly from the official release channels. All known affected branches are receiving the fixes. The project reiterates that 7.1.3 is a security release that should be applied ASAP.

Files impacted by the fixes span administrative JavaScript, export tools, embedded content handling, HTTP request processing, REST post operations, query building, and post-status hooks. The update does not alter any packages—only the core files.

Why This Matters for WordPress Sites

WordPress powers a huge chunk of the internet’s content-management systems—blogs, news sites, corporate portals, and more. Sites that allow user comments, embed content, export data, handle HTTP requests from visitors, or offer roles beyond just “Subscriber” are potentially exposed to many of the weaknesses fixed here. Until now, some flaws could have allowed attackers to execute scripts in the browser, access unpublished or private content, disrupt workflows, or even indirectly tamper with databases.

Moreover, the lack of CVE numbers or proof of active exploitation doesn’t lower the risk. Attackers often reverse-engineer fixes to craft exploits. Admins leaving this update undone are at risk, especially in higher-profile or high-traffic environments where impact is magnified.

For developers and plugin/theme authors, it’s also a reminder: user input, hooks, export formats, embedded content, and HTTP utilities are common attack surfaces. Sanitation, permission checks, and minimal exposure must remain priorities.

Effective immediately, every site running WordPress should deploy version 7.1.3. Monitor for signs of XSS or unauthorized content access, review role permissions, and check for unusual behavior tied to exports or embeds. Stay alert—patches like this often signal what attackers are likely probing next.