WordPress 7.1.1 Security Update Addresses 11 Vulnerabilities, Promotes Urgent Upgrade

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Urgent Update: WordPress Releases Version 7.1.1 with Critical Security Fixes

WordPress administrators are urged to promptly implement updates following the release of version 7.1.1, which encompasses a total of 11 security remedies alongside 17 core bug corrections and an additional 19 adjustments within the Block Editor.

Users can access this vital update via WordPress.org or directly through their dashboard by navigating to the Updates section and selecting “Update Now.” Websites equipped with automatic background updates will initiate the process autonomously.

The suite of security mitigations addresses a variety of vulnerabilities. Noteworthy among them is a stored cross-site scripting (XSS) vulnerability within the wpautop() function that permits unauthorized visitors to inject malicious scripts, contingent upon comment approval.

Additionally, a stored XSS flaw exists in certain themes that facilitate custom headers. This release rectifies an authenticated path traversal issue within the WP REST Templates Controller, and an arbitrary post overwrite vulnerability accessible to users with Contributor roles and above.

Further corrective measures target XML-RPC functionalities that allowed the publication of customize_changeset posts, circumventing edit_css protocols.

A significant oversight in attachment_submitbox_metadata() that potentially exposed private parent-post titles has been addressed, as has a lack of authorization checks that revealed draft or pending post slugs to Contributors and higher-level users.

Previously, any authenticated individual could transmogrify comment parentage, and specially designed URLs had the capability to automatically install and preview inactive themes from WordPress.org. Moreover, site administrators could enable network activation for installed Network-only plugins.

Attribution for the discovery of these issues is divided between external researchers and the WordPress development team.

Jeremy Felt and Ben Bidner, members of the WordPress Security Team, identified three vulnerabilities collectively, while Anthropic contributed two findings, and Rafie Muhammad of Awesome Motive, Inc. reported the wpautop() vulnerability.

Version 7.1.1 is categorized as a short-cycle release, with the subsequent major iteration, version 7.2, anticipated in December.

Security patches are being backported as deemed necessary to all branches still eligible, tracing back to version 4.7.

These backports are actively underway and will be released as they are completed. It is important to note that only the newest version of WordPress continues to receive active support.

Close-up of the WordPress app download page on a tablet, showing its logo, rating, and a blue cloud icon.

This launch follows a series of security updates, with version 7.0.4 being introduced in August, incorporating a solitary security fix, subsequent to version 7.0.3, which addressed multiple vulnerabilities earlier that same month.

Additionally, July’s version 7.0.2 rectified one critical and one high-severity issue, prompting the team to enable mandatory updates through the auto-update system for impacted sites due to their critical nature.

The 7.1 series, aptly dubbed “Mary Lou” in homage to the esteemed jazz pianist Mary Lou Williams, was officially released on August 19.

Notably, the announcement does not disclose a severity rating for any of the 11 vulnerabilities nor enumerate the number of sites that remain on earlier versions necessitating backports.

Source link: Technobezz.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading