WordPress 7.1.3 Addresses SQL Injection and Stored XSS Vulnerabilities

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

WordPress Unveils Version 7.1.3: A Crucial Security and Maintenance Update

On Tuesday, WordPress unveiled version 7.1.3, an essential update focused on security and maintenance, addressing seven vulnerabilities in the core platform while rectifying four bugs.

The announcement of this release acknowledges contributions from AI firm Anthropic for three of the seven identified vulnerabilities.

Additionally, security firms Trail of Bits and Patchstack each contributed one report, supplemented by findings from a group of independent researchers and WordPress’s own security team.

Notably, the organization has refrained from publishing CVE identifiers or severity assessments for the vulnerabilities, opting instead to provide succinct, one-line descriptions of each issue.

The vulnerability deemed most concerning involves a stored cross-site scripting (XSS) flaw located on the Comments administration screen, reported by Thomas Chauchefoin from Trail of Bits.

In a stored XSS scenario, a nefarious script gets insidiously embedded within the site, executing later in an unsuspecting user’s browser.

Here, the catalyst is a pending comment; the malignant script lies dormant in the moderation queue, triggering when an administrator or moderator accesses that page.

Anthropic’s findings encompass a significant second-order SQL injection vulnerability within the WXR exporter—a utility that facilitates the exportation of posts, comments, and assorted content in XML format.

In second-order injections, the attacker’s input initially remains inert, only morphing into an exploit when it is reused in a subsequent database query, specifically during an export operation.

Furthermore, the company identified a denial-of-service vulnerability withinWP_Http::make_absolute_url(), a method employed by WordPress’s HTTP layer to transform relative links into complete URLs.

The final report from Anthropic highlighted a permissions flaw that enabled users with the Author role to designate posts as sticky, unlawfully pinning them to the pinnacle of the blog’s main page, a function typically restricted to Editors and higher-level roles.

Patchstack’s Ananda Dhakal discovered that comments on private and unpublished posts could be accessed by visitors lacking login credentials.

Concurrently, researchers Zhengyu Liu, Jingcheng Yang, and Gavin Zhong uncovered an XSS vulnerability related to WordPress’s Imgur embeds, which convert pasted Imgur links into embedded images.

The seventh fix, attributed to Alex Concha from the WordPress security team, pertains to the dynamic {status}_{type} hook.

WordPress constructs this hook’s nomenclature based on a post’s status and type; for instance, publish_post.

Certain parameters influencing this name were found susceptible to forgery, enabling it to resemble a different, unassociated action.

Version 7.1.3 marks the fifth security release from WordPress since the outset of August, following version 7.1.1 released on September 17, which rectified 11 vulnerabilities, including two initially identified by Anthropic.

A follow-up release, version 7.1.2, emerged merely five days later to address CVE-2026-87902—a previously exploited unauthenticated path traversal vulnerability linked to page template resolution.

Notably, WordPress has not reported any active exploitation of the vulnerabilities rectified in the 7.1.3 update.

Websites with automatic background updates enabled will adopt version 7.1.3 autonomously. Alternatively, administrators can manually initiate the update via the Updates screen in the Dashboard or download the release directly.

WordPress has indicated its commitment to backport these fixes to every version still eligible for security updates, stretching back to version 4.7.

white and blue printer paper

These backports are underway and will be rolled out as they are finalized, indicating that sites operating on older branches may not yet enjoy full protection.

“Only the most recent version of WordPress is actively supported,” the organization stated.

Source link: Cyberkendra.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading