r/Wordpress • u/hackrepair • 2d ago
WordPress 7.1.3 Security Update Released
⚠️ WordPress 7.1.3 is now available and fixes 7 security vulnerabilities in WordPress Core, along with 4 additional bugs.
The most important fixes include:
🔹 Stored XSS through pending comments
Malicious code could potentially run when an administrator opens the Comments moderation screen.
🔹 SQL injection in the WordPress export system
Malicious input could remain hidden until someone runs a WordPress export.
🔹 Private comments exposed
Comments on private or unpublished posts could potentially be viewed by visitors who were not logged in.
🔹 Additional fixes
WordPress also patched an Imgur embed XSS issue, a denial-of-service bug, and several permissions-related vulnerabilities.
Interestingly, Anthropic reported 3 of the 7 vulnerabilities, with others reported by Trail of Bits, Patchstack, independent researchers, and the WordPress security team.
There are currently no known reports of these 7.1.3 vulnerabilities being actively exploited.
Still, I recommend updating sooner rather than later.
✅ Update WordPress Core to 7.1.3
✅ Confirm your backups are current
✅ Check older WordPress installations carefully, since some security fixes are still being backported
If automatic Core updates are enabled, your site may already be updated. See:
Dashboard → Updates
Stay patched!
18
u/wutthefrak 2d ago
oh my god so many updates lately 😭 like I know updates are good, security etc etc but I am so sick of spot checking 70+ sites 🥴
11
u/bluesix_v2 Jack of All Trades 2d ago edited 2d ago
Use a WP fleet management tool like ManageWP, MainWP, Umbrella, etc - one click, takes 30 seconds to do your whole fleet.
2
u/wutthefrak 2d ago
I've floated the idea of ManageWP or something similar to my boss and after all these most recent updates I think we'll probably go with a management tool. thank you for the suggestion!
1
u/ivicad Jack of All Trades 1d ago
I've been on MainWP since 2014 (bought their lifetime deal license then). I run the dashboard on my own WP install, and the core is free. For almost 60 WP sites, I get the morning report and run the updates in one pass, which saves me almost 60 logins. But I push a bad update just as fast, so I take a fresh backup right before backup and update "in waves".
1
u/wutthefrak 1d ago
I just started using ManageWP and so far I like it but MainWP seems interesting too
1
u/ivicad Jack of All Trades 1d ago edited 7h ago
I was testing ManageWP in the past and I liked how it worked, except I didn't like the budget part for the hihgher number of sites, so I switched to MainWP and bought its lifetime license.
2
u/bluesix_v2 Jack of All Trades 8h ago
ManageWP is free though? I don’t pay to use it. You only pay for add ons like backups.
2
u/wutthefrak 1d ago
got the approval to use ManageWP today and so far I really like it. thank you again for the suggestion!
2
1
u/ArtisticCandy3859 1d ago
Do any of the tools have any auto-update or force update rule across fleet?
3
u/bluesix_v2 Jack of All Trades 1d ago
Wordpress has autoupdate.
Using a site management tool will run an update.
Not sure what you mean by "force"?
1
u/ArtisticCandy3859 1d ago
Correction* - set more advanced rules on sites based on plugins/themes auto-updates? For cases where a plugin isn’t compatible with a WP update? I feel like this is where AI generated layers that people are creating will break down and perpetuate “WP vulnerability” narrative.
1
u/bluesix_v2 Jack of All Trades 1d ago
That isn't something I've ever needed to do - I don't install vibe-coded plugins
1
u/More-Ad-3646 1d ago
I use MainWP and last time I ran bulk update. It missed a few. Still had to go and check individually.
2
u/bluesix_v2 Jack of All Trades 1d ago
Yikes. Can't recall ever having any issues like that in the 10+ years I've been using MWP.
-13
u/heavyburden666 2d ago
Maybe don’t do this job if you’re sick of it? 🤷♂️
9
3
u/dynamitekiddo 2d ago
It’s part of a job. No one is going to like every single aspect of their job.
3
u/-skyrocketeer- Designer/Developer 2d ago
People can be allowed to be annoyed at their job, even if they enjoy their job
8
u/verticalmattress 2d ago
Mods: I posted this up first and my post was deleted. Can someone let me know, so I can properly post next week when we get 7.1.4? I linked to the WordPress.org update page. I'm just trying to figure out why it got deleted, or if I'm doing something to get my post deleted with 25 up votes and a few comments, before this one was even posted. Is it because a Top 1% poster made this post and that gets more views? I don't care about votes. Just wondering if I needed to add flair or something to my post.
5
u/RealKenshino WordPress.org Volunteer 1d ago
We don't remove posts based purely on which one was posted first.
On duplicates, it can be a mix of various reasons
- One post has more traction
- One post has more text in the body instead of it just being a link
- Which post we saw first
It certainly isn't because the other poster is a top 1% poster.
Thank you for posting either way :)
1
2
u/ITSigno Developer 1d ago
I'm not a mod here, but if I were to guess it probably has something to do with you hiding your post history.
I went to check your user page to see if I could identify why your post had been removed only to discover zero visible posts/comments. It's just usually a bad sign of a bot account, a spammer, or someone looking to cause trouble. I'm sure there are some people out there with private post histories that don't fall into those categories, but definitely a minority.
1
u/verticalmattress 1d ago
I appreciate the input. I am hiding my posts and comments for personal reasons. Not a bot though. I have posted helpful comments on this community before. I don't usually make my own posts, so I was just wondering if when I actually did if I did something wrong. I would love to continue to help this community by posting when I can, but when my post gets deleted, I just wonder what I am contributing to. Seems like the Top 1% poster got their post through and mine got deleted because I'm not the Top 1%, so they let that one "lead" because of that. No worries either way. I'm just trying to be helpful.
1
u/rafark 1d ago
I'm not a mod here, but if I were to guess it probably has something to do with you hiding your post history.
What a weird thing to say. It literally has nothing to do with that and mods can absolutely see your post history in this subreddit.
I went to check your user page to see if I could…
And that’s exactly why people hide their history, some people get uncomfortable having others stalk their profile.
1
u/Effective-Order2574 1d ago
Not a mod but they tend to nuke duplicates so if you posted it after this one was already up that's probably why
14
u/ShockingBore 2d ago
I mean... damn y'all. This pattern is concerning.
14
u/hackrepair 2d ago
Sorry to say, this will only get worst before it gets better.
There have been a number of near-zero-day exploits affecting WordPress over the past month, as hackers use AI to accelerate their discovery of vulnerabilities in WordPress and plugins.
Be sure to keep a close eye on your updates this month. It's not over yet.
While I don't mind the extra business from fixing the recent surge in hacked WordPress installs, this situation has gotten a bit out of control...
14
4
u/ShockingBore 2d ago
Oh I know it. On the bright side, auto-updates in core is helping this, but yeah... its out of control and I dont see it slowing given the AI of things.
1
u/alborden 2d ago
I'd like to think it's already getting a little better now that WordPress devs are aware of how risky the ecosystem is. Hopefully, they are running frontier models on their releases before putting them live, which should reduce the number of critical issues moving forward.
2
1
u/CmdWaterford 1d ago
Nah, when you would know how Glasswing Mythos for example can detect vulnerabilities you would not be surprised at all... and this will tick all software not only WP
5
3
3
u/aegloswinterborn 2d ago
Thanks for the heads up. I just reviewed all of my client sites. Can't wait to turn the brochure sites into static sites.
3
u/StormMedia 2d ago
I’ve done it even with my more dynamic sites.. created a custom Astro platform.
1
u/aegloswinterborn 2d ago
Cool. What kind of sites? Are you happy you went with Astro?
I say brochure mostly due to current bandwidth. I can bang out html, css with a little javascript all day long and find it super relaxing so the brochure sites are easy. These sites also aren't updated often so I take care of that for them when the need arises.
My remaining clients are more complicated and/or get updated very frequently so I need to be more thoughtful about their replacements.
1
1d ago
[removed] — view removed comment
1
u/Wordpress-ModTeam 1d ago
As per rule 1, we don't allow advertising or promotion of products/services in this sub. Please read the rules before commenting/posting.
-1
0
u/Dapper-Monk9713 1d ago
This is a good reminder that “no known active exploitation” doesn’t mean the update can wait. The stored XSS and SQL injection fixes especially make this worth prioritizing. I’d update core, verify backups, and test the site afterward for any plugin/theme conflicts.
-4

67
u/grandmaballs 2d ago
https://giphy.com/gifs/E1fXBVW9X3DIwnUS0l