WordPress 7.1.3 Addresses 7 Security Issues and 1 Major Vulnerability

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

WordPress has unveiled a pivotal security update, designated as Version 7.1.3, which aims to rectify seven identified security vulnerabilities alongside four notable bug fixes.

Among the vulnerabilities addressed are a stored cross-site scripting (XSS) flaw, a denial-of-service (DoS) issue, and five additional vulnerabilities of undetermined severity. The platform strongly advises users to implement the updates at the earliest opportunity.

Identified Vulnerabilities

The update highlights seven critical vulnerabilities:

  1. Stored XSS
  2. Denial-of-Service (DoS) vulnerability
  3. Second-Order SQL Injection
  4. Weakness permitting Author role users to designate posts as sticky
  5. Unauthenticated exposure of comments
  6. Imgur embeds susceptible to XSS attacks
  7. Parameter forgery potentially leading to action name collisions

Notably, the official notification does not provide severity ratings, CVSS scores, or descriptions of these vulnerabilities, nor does it disclose if they are currently being exploited in active environments. Nevertheless, urgent updates to WordPress sites are highly recommended.

The security patches will also be backported to older WordPress versions, up to Version 4.7, which are still qualified for security updates. These backports are presently underway and will be rolled out for legacy versions as they are finalized.

Bug Fixes

This release includes four bug fixes, three of which pertain to relatively benign issues that detract from user experience, while the fourth addresses a critical flaw.

Two of the fixes rectify issues with oEmbed endpoints that return a 404 error message—one associated with a music promotion platform and the other with an eCard humor website.

Another fix addresses a bug that could cause an oversized website icon image in the admin toolbar, while the fourth could trigger a fatal error, which sounds alarming but is likely less severe than it appears.

Critical Issue Results in Fatal Error

The aforementioned critical bug can impede image uploads, resulting in a fatal error on hosting environments that lack the optional DOM library, thereby hindering site administrators from uploading media.

According to the related WordPress ticket, the image upload process ceased entirely, preventing any image from being uploaded. This is arguably less catastrophic than a total page or site breakdown.

The root of this issue lies in the absence of PHP’s DOM extension (ext-dom), which is responsible for providing the DOMDocument and DOMXPath classes that WordPress intended to utilize. Although WordPress advocates for the extension, it does not mandate its presence.

The introduction of WordPress 7.0 incorporated code utilizing DOMDocument without preliminary checks for the extension’s existence.

A computer monitor displays WordPress 7.0 Redesigned Revolutionized with feature overview, surrounded by screens showing editing tools.

Consequently, on hosts lacking the component, image uploads could trigger a fatal error that entirely disrupts the process.

The WordPress ticket detailing this issue categorizes the bug as critical; however, a core committer noted its rarity, as it took 134 days post-release for the first report to surface, indicating that most hosting providers already support the DOM extension, thus limiting the impact of this critical flaw.

Source link: Searchenginejournal.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading