FIXED! WordPress 7.1.3 has fixed 7 vulnerabilities that led to XSS, SQL Injection, and information disclosure!
ATTENTION! WordPress 7.1.3 has fixed 7 vulnerabilities that lead to XSS, SQL Injection, and information disclosure!
The WordPress 7.1.3 version was released on October 6, 2026. This release is a security and technical service update, in which 7 security vulnerabilities and 4 technical errors have been fixed. The WordPress team recommends installing this version as soon as possible.
The new update fixes issues that can lead to Cross-Site Scripting (XSS), SQL Injection, unauthorized information disclosure, incorrect permission checks, denial of service, and other security problems.
The official WordPress announcement did not include CVE identifiers or general CVSS scores for these vulnerabilities. Therefore, it is not accurate to classify all of them as "critical." However, some vulnerabilities can pose serious risks to sites that process user-submitted data, comments, external content, and the WXR export function.
What vulnerabilities were fixed in WordPress 7.1.3?
According to the official WordPress security announcement, the following 7 security issues were fixed in the new version:
- Stored XSS vulnerability in the Comments page that stores data; WP_Http::make_absolute_url() function; DoS vulnerability in the WXR export mechanism; a second SQL Injection vulnerability in the WXR export mechanism;
- Ability for users with Author permission to make posts "sticky";
- Unauthenticated disclosure of comments related to private and unpublished posts;
- XSS vulnerability in Imgur embeds; where parameters passed to the {status}_{type} hook cause action name collisions.
Although some of these issues relate to specific functions, all of them indicate the need to update the WordPress core.
XSS Attack Stored via Comments
One of the most important fixes is related to the Comments page in the WordPress administration panel.
This vulnerability falls under the category of Stored Cross-Site Scripting (XSS). The problem can occur when working with stored comments—that is, unverified comments.
In a Stored XSS attack, malicious JavaScript code is placed in the user-submitted data, and it can be executed in the browser of another user who later views this data.
This situation is particularly important for administrators, as they might see malicious code when reviewing comments submitted by visitors to the site.
This vulnerability was identified by Thomas Chauchefoin from Trail of Bits and reported to the WordPress security team. The official WordPress announcement did not disclose the exact payload of the attack or all the conditions required for exploitation.
Therefore, administrators should pay special attention to this update when using user comments on live websites.
Another XSS vulnerability in Imgur embeds
Another XSS vulnerability related to Imgur embeds was also fixed in WordPress 7.1.3.
WordPress allows embedding content from various external platforms into website pages. While this mechanism is convenient for users, errors in the process of processing external content can lead to security problems.
This vulnerability was reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong.
This issue differs from XSS that occurs through comments. One relates to managing user comments, and the other relates to the process of embedding external Imgur content.
Therefore, administrators who use external media and embedded content on the site should not delay updating the WordPress core.
SQL Injection Vulnerability in WXR Export
Another important issue fixed in WordPress 7.1.3 is the second SQL Injection vulnerability in the WXR export mechanism.
WXR is the format used to export WordPress site data, which can be transferred to another WordPress installation or used for backup purposes.
The SQL Injection vulnerability can allow an attacker to influence the formation of queries sent to the database by the application.
This situation is recorded as "second-order SQL injection." In this type of attack, malicious values are initially entered into the system or stored, and later cause the formation of a dangerous SQL query when another process uses this value.
The vulnerability was reported by Anthropic researchers. The official WordPress announcement did not detail all the technical steps of exploitation or the exact conditions required by an attacker. Therefore, it is not correct to interpret this vulnerability as automatically gaining full control of the database of any user.
However, updating the core is important for sites that use WXR export.
Comments of Private Posts can be Disclosed Without Authorization
The issue of unauthenticated disclosure of comments related to private and unpublished posts was also fixed in WordPress 7.1.3.
The main risk here is that a user or attacker gains access to information that should not be visible under normal circumstances.
For example, there might be comments related to material that the site administration has not yet released to the public. If the mechanism for controlling access to these comments is flawed, there is a possibility that these comments will be visible to an unauthorized user.
This vulnerability was identified by Ananda Dhakal from Patchstack. The WordPress announcement indicated that the problem is related to the disclosure of comments, but it did not claim that the private post itself is fully disclosed.
This is particularly important for organizations that use internal, editing processes, or unpublished materials.
Users with Author Permission Can Make Posts "Sticky"
In WordPress, the Author role usually has limited rights to create and manage their posts.
In version 7.1.3, the legal control issue that allowed Author-level users to make posts sticky, i.e., display them at the top of the site, has been fixed.
This does not necessarily lead to direct code execution, but improper management of permissions is a security concern.
This vulnerability was also reported by Anthropic. In WordPress 7.1.3, the necessary rights to check for the sticky status of a post via the REST API have been strengthened.
This is particularly important for corporate sites with multiple authors and editors.
DoS Vulnerability in the WP_Http::make_absolute_url() function
Another fix is related to the WP_Http::make_absolute_url() function in WordPress's HTTP handling mechanism.
This function is used to convert relative URL addresses to absolute URLs.
Exploiting this mechanism can lead to excessive consumption of server resources or negatively affect the functioning of the service in some situations. Such attacks are usually called Denial-of-Service (DoS) attacks.
The official WordPress announcement also showed that Anthropic identified this vulnerability. However, the exact request format, resource consumption, or exploitation conditions required for the attack were not disclosed.
Therefore, this issue should be assessed as a security flaw to be fixed via the update, rather than an explicit attack scenario.
Action Name Collisions in the {status}_{type} hook
Another important change in WordPress 7.1.3 is related to the {status}_{type} hook mechanism.
Passing parameters to this hook can cause collisions in action names in some situations.
Such problems can cause different events in the program to be processed with the same name and lead to the execution of unexpected code paths.
This vulnerability was identified by Alex Concha from the WordPress security team. The fix strengthens the execution of dynamic hooks related to post status and type only for states and types that have been registered.
WordPress 7.1.3 is Not Just a Simple Technical Update
It is incorrect to consider WordPress 7.1.3 as a simple "maintenance" update.
According to the official information, there are 7 security and 4 technical fixes in the release. Therefore, the WordPress project recommended that users install the update promptly.
The update changes parts related to the administrator panel JavaScript code, WXR export, REST API, posts, HTTP mechanism, external embeds, and the database.
In this sense, installing the updated version of the WordPress core not only fixes one problem but also closes several attack vectors simultaneously.
What Should Users Using Older WordPress Versions Do?
WordPress backports security fixes to older networks that are still supported in necessary cases. The official information shows that security fixes are being backported to relevant networks up to version 4.7. However, as WordPress specifically stated, only the latest version is actively supported.
Therefore, organizations should move to the most current version as much as possible, rather than relying on older networks for a long time.
The WordPress official releases archive shows that 7.1.3 is the latest version of the 7.1 series.
Recommendations for WordPress Site Administrators
After this security update, the following actions are recommended for administrators:
1. Update the WordPress core immediately. Go to Dashboard → Updates → Update Now to get version 7.1.3 or use the official release of WordPress. Updates can start automatically for sites that support automatic background updates.
2. Create a backup before the update. Saving a separate backup of the files and database allows for restoring the site in case of problems after the update.
3. Check Plugins and Themes as well. Updating the WordPress core alone is not enough. Outdated or vulnerable plugins and themes can also become entry points for attackers.
4. Review User Permissions. It is necessary to check the list of users with Author, Editor, and Administrator roles, remove unnecessary permissions, and block unused accounts.
5. Monitor Comments. Since comments submitted by users can be used in XSS attacks, caution should be exercised regarding unknown or suspicious content.
6. Check External Content. Embeds and other media content obtained from external sources like Imgur need regular monitoring.
7. Monitor Logs. It is important to analyze logins to administrator accounts, REST API requests, unusual post changes, and unknown user activities.
8. Re-check the Site After the Update. If the site was running on an older vulnerable version, it is important to check not only for updates but also for suspicious PHP files, administrator accounts, plugins, and configuration changes.
Have the Vulnerabilities Already Been Exploited?
An important point is that the official announcement for WordPress 7.1.3 does not provide information that these seven vulnerabilities have been exploited in real attacks. Furthermore, CVE numbers and CVSS scores are not included in the official information.
Therefore, it is not correct to automatically call these vulnerabilities "actively exploited critical vulnerabilities."
However, after security updates are publicly announced, attackers may try to identify the differences in the patched code. Therefore, it is the most important measure for WordPress administrators not to delay security updates.
The WordPress 7.1.3 version is an important security update for site administrators. It fixes a total of 7 vulnerabilities related to XSS, SQL Injection, unauthorized information disclosure, incorrect permission management, DoS, and other security issues.
In particular, WordPress sites that process user comments, embed external content, use WXR export, or have a multi-user management system need to pay special attention to this update.
WordPress itself also marked this release as a security update and recommended that sites be updated promptly.
Dear Site Administrators! Please regularly update the WordPress core, plugins, and themes, control the permissions granted to users, protect administrator accounts, and continuously monitor the site logs.
A single delayed update in cybersecurity can become another opportunity for an attacker.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.