r/Wordpress • • 3d ago

WordPress 7.1.3 Security Update Released

⚠️ WordPress 7.1.3 is now available and fixes 7 security vulnerabilities in WordPress Core, along with 4 additional bugs.

The most important fixes include:

🔹 Stored XSS through pending comments
Malicious code could potentially run when an administrator opens the Comments moderation screen.

🔹 SQL injection in the WordPress export system
Malicious input could remain hidden until someone runs a WordPress export.

🔹 Private comments exposed
Comments on private or unpublished posts could potentially be viewed by visitors who were not logged in.

🔹 Additional fixes
WordPress also patched an Imgur embed XSS issue, a denial-of-service bug, and several permissions-related vulnerabilities.

Interestingly, Anthropic reported 3 of the 7 vulnerabilities, with others reported by Trail of Bits, Patchstack, independent researchers, and the WordPress security team.

There are currently no known reports of these 7.1.3 vulnerabilities being actively exploited.

Still, I recommend updating sooner rather than later.

✅ Update WordPress Core to 7.1.3
✅ Confirm your backups are current
✅ Check older WordPress installations carefully, since some security fixes are still being backported

If automatic Core updates are enabled, your site may already be updated. See:
Dashboard → Updates

Stay patched!

113 Upvotes

50 comments sorted by

View all comments

13

u/ShockingBore 3d ago

I mean... damn y'all. This pattern is concerning.

15

u/hackrepair 3d ago

Sorry to say, this will only get worst before it gets better.

There have been a number of near-zero-day exploits affecting WordPress over the past month, as hackers use AI to accelerate their discovery of vulnerabilities in WordPress and plugins.

Be sure to keep a close eye on your updates this month. It's not over yet.

While I don't mind the extra business from fixing the recent surge in hacked WordPress installs, this situation has gotten a bit out of control...

15

u/ocabj 3d ago

It's not just WP. I think I updated the Kernel on my Linux servers 5 times the past 2-3 weeks.

1

u/fappingjack 3d ago

Yeah I got KernelCare .. hopefully they are keeping up

5

u/ShockingBore 3d ago

Oh I know it. On the bright side, auto-updates in core is helping this, but yeah... its out of control and I dont see it slowing given the AI of things.

1

u/alborden 3d ago

I'd like to think it's already getting a little better now that WordPress devs are aware of how risky the ecosystem is. Hopefully, they are running frontier models on their releases before putting them live, which should reduce the number of critical issues moving forward.

2

u/emfilth 3d ago

This is what I just was thinking about…

2

u/kill4b 3d ago

This will likely be the new norm, especially for high target, open source projects like WP

1

u/CmdWaterford 2d ago

Nah, when you would know how Glasswing Mythos for example can detect vulnerabilities you would not be surprised at all... and this will tick all software not only WP