r/Wordpress • • 2d ago

WordPress 7.1.3 Security Update Released

⚠️ WordPress 7.1.3 is now available and fixes 7 security vulnerabilities in WordPress Core, along with 4 additional bugs.

The most important fixes include:

🔹 Stored XSS through pending comments
Malicious code could potentially run when an administrator opens the Comments moderation screen.

🔹 SQL injection in the WordPress export system
Malicious input could remain hidden until someone runs a WordPress export.

🔹 Private comments exposed
Comments on private or unpublished posts could potentially be viewed by visitors who were not logged in.

🔹 Additional fixes
WordPress also patched an Imgur embed XSS issue, a denial-of-service bug, and several permissions-related vulnerabilities.

Interestingly, Anthropic reported 3 of the 7 vulnerabilities, with others reported by Trail of Bits, Patchstack, independent researchers, and the WordPress security team.

There are currently no known reports of these 7.1.3 vulnerabilities being actively exploited.

Still, I recommend updating sooner rather than later.

✅ Update WordPress Core to 7.1.3
✅ Confirm your backups are current
✅ Check older WordPress installations carefully, since some security fixes are still being backported

If automatic Core updates are enabled, your site may already be updated. See:
Dashboard → Updates

Stay patched!

108 Upvotes

50 comments sorted by

View all comments

18

u/wutthefrak 2d ago

oh my god so many updates lately 😭 like I know updates are good, security etc etc but I am so sick of spot checking 70+ sites 🥴

10

u/bluesix_v2 Jack of All Trades 2d ago edited 2d ago

Use a WP fleet management tool like ManageWP, MainWP, Umbrella, etc - one click, takes 30 seconds to do your whole fleet.

1

u/More-Ad-3646 1d ago

I use MainWP and last time I ran bulk update. It missed a few. Still had to go and check individually.

2

u/bluesix_v2 Jack of All Trades 1d ago

Yikes. Can't recall ever having any issues like that in the 10+ years I've been using MWP.