WordPress Unveils Version 7.1.3: A Crucial Security and Maintenance Update
On Tuesday, WordPress unveiled version 7.1.3, an essential update focused on security and maintenance, addressing seven vulnerabilities in the core platform while rectifying four bugs.
The announcement of this release acknowledges contributions from AI firm Anthropic for three of the seven identified vulnerabilities.
Additionally, security firms Trail of Bits and Patchstack each contributed one report, supplemented by findings from a group of independent researchers and WordPress’s own security team.
Notably, the organization has refrained from publishing CVE identifiers or severity assessments for the vulnerabilities, opting instead to provide succinct, one-line descriptions of each issue.
The vulnerability deemed most concerning involves a stored cross-site scripting (XSS) flaw located on the Comments administration screen, reported by Thomas Chauchefoin from Trail of Bits.
In a stored XSS scenario, a nefarious script gets insidiously embedded within the site, executing later in an unsuspecting user’s browser.
Here, the catalyst is a pending comment; the malignant script lies dormant in the moderation queue, triggering when an administrator or moderator accesses that page.
Anthropic’s findings encompass a significant second-order SQL injection vulnerability within the WXR exporter—a utility that facilitates the exportation of posts, comments, and assorted content in XML format.
In second-order injections, the attacker’s input initially remains inert, only morphing into an exploit when it is reused in a subsequent database query, specifically during an export operation.
Furthermore, the company identified a denial-of-service vulnerability withinWP_Http::make_absolute_url(), a method employed by WordPress’s HTTP layer to transform relative links into complete URLs.
The final report from Anthropic highlighted a permissions flaw that enabled users with the Author role to designate posts as sticky, unlawfully pinning them to the pinnacle of the blog’s main page, a function typically restricted to Editors and higher-level roles.
Patchstack’s Ananda Dhakal discovered that comments on private and unpublished posts could be accessed by visitors lacking login credentials.
Concurrently, researchers Zhengyu Liu, Jingcheng Yang, and Gavin Zhong uncovered an XSS vulnerability related to WordPress’s Imgur embeds, which convert pasted Imgur links into embedded images.
The seventh fix, attributed to Alex Concha from the WordPress security team, pertains to the dynamic {status}_{type} hook.
WordPress constructs this hook’s nomenclature based on a post’s status and type; for instance, publish_post.
Certain parameters influencing this name were found susceptible to forgery, enabling it to resemble a different, unassociated action.
Version 7.1.3 marks the fifth security release from WordPress since the outset of August, following version 7.1.1 released on September 17, which rectified 11 vulnerabilities, including two initially identified by Anthropic.
A follow-up release, version 7.1.2, emerged merely five days later to address CVE-2026-87902—a previously exploited unauthenticated path traversal vulnerability linked to page template resolution.
Notably, WordPress has not reported any active exploitation of the vulnerabilities rectified in the 7.1.3 update.
Websites with automatic background updates enabled will adopt version 7.1.3 autonomously. Alternatively, administrators can manually initiate the update via the Updates screen in the Dashboard or download the release directly.
WordPress has indicated its commitment to backport these fixes to every version still eligible for security updates, stretching back to version 4.7.

These backports are underway and will be rolled out as they are finalized, indicating that sites operating on older branches may not yet enjoy full protection.
“Only the most recent version of WordPress is actively supported,” the organization stated.
Source link: Cyberkendra.com.






