WordPress.org released version 7.1.3 on October 6. It includes 7 security fixes and 4 bug fixes. WordPress.org recommends updating immediately.

This is the third security release in about three weeks, after 7.1.2 two weeks ago and 7.1.1 before it.

What was fixed

WordPress.org lists these issues:

  • Stored cross-site scripting (malicious script saved on your site) on the Comments admin page, triggered through pending comments. Trail of Bits reported it.
  • A denial-of-service issue in WP_Http::make_absolute_url(), reported by Anthropic.
  • A second-order SQL injection in WordPress export files, reported by Anthropic.
  • A weakness that let Author-role users make posts sticky, reported by Anthropic.
  • Unauthenticated disclosure of comments on private and unpublished posts, reported by Patchstack.
  • Cross-site scripting in Imgur embeds.
  • Forgeable values passed to a hook, which could cause action name collisions. WordPress’s own security team reported it.

The comment-related fixes matter most for sites that accept public comments or hold unpublished content.

What to do

Open your Dashboard, click Updates, then Update Now. Sites with automatic background updates will update on their own.

WordPress.org says it is backporting the fixes to older branches, going back to 4.7. Only the most recent version is actively supported, so move to 7.1.3 if you can.


End of article