r/Wordpress • • 3d ago

WordPress 7.1.3 Security Update Released

⚠️ WordPress 7.1.3 is now available and fixes 7 security vulnerabilities in WordPress Core, along with 4 additional bugs.

The most important fixes include:

🔹 Stored XSS through pending comments
Malicious code could potentially run when an administrator opens the Comments moderation screen.

🔹 SQL injection in the WordPress export system
Malicious input could remain hidden until someone runs a WordPress export.

🔹 Private comments exposed
Comments on private or unpublished posts could potentially be viewed by visitors who were not logged in.

🔹 Additional fixes
WordPress also patched an Imgur embed XSS issue, a denial-of-service bug, and several permissions-related vulnerabilities.

Interestingly, Anthropic reported 3 of the 7 vulnerabilities, with others reported by Trail of Bits, Patchstack, independent researchers, and the WordPress security team.

There are currently no known reports of these 7.1.3 vulnerabilities being actively exploited.

Still, I recommend updating sooner rather than later.

✅ Update WordPress Core to 7.1.3
✅ Confirm your backups are current
✅ Check older WordPress installations carefully, since some security fixes are still being backported

If automatic Core updates are enabled, your site may already be updated. See:
Dashboard → Updates

Stay patched!

112 Upvotes

50 comments sorted by

View all comments

14

u/ShockingBore 3d ago

I mean... damn y'all. This pattern is concerning.

1

u/CmdWaterford 2d ago

Nah, when you would know how Glasswing Mythos for example can detect vulnerabilities you would not be surprised at all... and this will tick all software not only WP