WordPress has unveiled a pivotal security update, designated as Version 7.1.3, which aims to rectify seven identified security vulnerabilities alongside four notable bug fixes.
Among the vulnerabilities addressed are a stored cross-site scripting (XSS) flaw, a denial-of-service (DoS) issue, and five additional vulnerabilities of undetermined severity. The platform strongly advises users to implement the updates at the earliest opportunity.
Identified Vulnerabilities
The update highlights seven critical vulnerabilities:
- Stored XSS
- Denial-of-Service (DoS) vulnerability
- Second-Order SQL Injection
- Weakness permitting Author role users to designate posts as sticky
- Unauthenticated exposure of comments
- Imgur embeds susceptible to XSS attacks
- Parameter forgery potentially leading to action name collisions
Notably, the official notification does not provide severity ratings, CVSS scores, or descriptions of these vulnerabilities, nor does it disclose if they are currently being exploited in active environments. Nevertheless, urgent updates to WordPress sites are highly recommended.
The security patches will also be backported to older WordPress versions, up to Version 4.7, which are still qualified for security updates. These backports are presently underway and will be rolled out for legacy versions as they are finalized.
Bug Fixes
This release includes four bug fixes, three of which pertain to relatively benign issues that detract from user experience, while the fourth addresses a critical flaw.
Two of the fixes rectify issues with oEmbed endpoints that return a 404 error message—one associated with a music promotion platform and the other with an eCard humor website.
Another fix addresses a bug that could cause an oversized website icon image in the admin toolbar, while the fourth could trigger a fatal error, which sounds alarming but is likely less severe than it appears.
Critical Issue Results in Fatal Error
The aforementioned critical bug can impede image uploads, resulting in a fatal error on hosting environments that lack the optional DOM library, thereby hindering site administrators from uploading media.
According to the related WordPress ticket, the image upload process ceased entirely, preventing any image from being uploaded. This is arguably less catastrophic than a total page or site breakdown.
The root of this issue lies in the absence of PHP’s DOM extension (ext-dom), which is responsible for providing the DOMDocument and DOMXPath classes that WordPress intended to utilize. Although WordPress advocates for the extension, it does not mandate its presence.
The introduction of WordPress 7.0 incorporated code utilizing DOMDocument without preliminary checks for the extension’s existence.

Consequently, on hosts lacking the component, image uploads could trigger a fatal error that entirely disrupts the process.
The WordPress ticket detailing this issue categorizes the bug as critical; however, a core committer noted its rarity, as it took 134 days post-release for the first report to surface, indicating that most hosting providers already support the DOM extension, thus limiting the impact of this critical flaw.
Source link: Searchenginejournal.com.






