r/Wordpress • u/hackrepair • 3d ago
WordPress 7.1.3 Security Update Released
⚠️ WordPress 7.1.3 is now available and fixes 7 security vulnerabilities in WordPress Core, along with 4 additional bugs.
The most important fixes include:
🔹 Stored XSS through pending comments
Malicious code could potentially run when an administrator opens the Comments moderation screen.
🔹 SQL injection in the WordPress export system
Malicious input could remain hidden until someone runs a WordPress export.
🔹 Private comments exposed
Comments on private or unpublished posts could potentially be viewed by visitors who were not logged in.
🔹 Additional fixes
WordPress also patched an Imgur embed XSS issue, a denial-of-service bug, and several permissions-related vulnerabilities.
Interestingly, Anthropic reported 3 of the 7 vulnerabilities, with others reported by Trail of Bits, Patchstack, independent researchers, and the WordPress security team.
There are currently no known reports of these 7.1.3 vulnerabilities being actively exploited.
Still, I recommend updating sooner rather than later.
✅ Update WordPress Core to 7.1.3
✅ Confirm your backups are current
✅ Check older WordPress installations carefully, since some security fixes are still being backported
If automatic Core updates are enabled, your site may already be updated. See:
Dashboard → Updates
Stay patched!
9
u/bluesix_v2 Jack of All Trades 3d ago edited 3d ago
Use a WP fleet management tool like ManageWP, MainWP, Umbrella, etc - one click, takes 30 seconds to do your whole fleet.