Key details

  1. WordPress 7.1.3 was released October 6, 2026.
  2. It contains seven security fixes and four bug fixes.
  3. The security fixes include stored XSS via pending comments and second-order SQL injection in WXR export.
  4. Another fix addresses unauthenticated disclosure of comments on private and unpublished posts.
  5. WordPress recommends updating immediately and says eligible older branches are receiving backports where necessary.

What builders should take away

  1. Update production sites to 7.1.3 rather than treating 7.1.2 as the current secure endpoint.
  2. Include pending-comment moderation screens in privileged XSS threat modelling.
  3. If workflows import or export WXR files, treat exported/imported content as untrusted data even when the dangerous effect is delayed.
  4. Track older-branch backports separately if an installation cannot yet move to 7.1.3.

What changed

WordPress released 7.1.3 on October 6 with seven security fixes and four bug fixes. The security set includes stored XSS on the Comments administration page exploitable via pending comments; a denial-of-service issue in WP_Http::make_absolute_url(); second-order SQL injection in WordPress WXR export; an Author-role weakness allowing posts to be made sticky; unauthenticated disclosure of comments on private and unpublished posts; XSS in Imgur embeds; and forgeable parameters passed to the {status}_{type} hook that can cause action-name collision. WordPress says fixes are being backported where necessary to branches eligible for security fixes, currently through 4.7.

Why it matters

This is a broad core-security release rather than a routine maintenance patch. Several issues cross trust boundaries builders commonly rely on: pending comments can reach an administrative XSS surface, private-post comments can be disclosed without authentication, and exported content can carry a second-order SQL-injection path. Operators should update rather than assume the previous 7.1.2 RCE patch left the branch current.

Seven fixes span several trust boundaries

The release touches administrative comment rendering, WXR export, HTTP URL handling, post permissions, private-content comments, embeds and dynamic hook naming. That breadth makes the operational recommendation simple: treat 7.1.3 as a security update, not a discretionary bug-fix release.

Pending comments are part of the attack surface

WordPress specifically says the stored XSS on the Comments administration page is exploitable through pending comments. That matters because content does not need to be publicly approved before it can reach a privileged review surface.

Older branches are receiving backports

WordPress says security fixes are being backported where necessary to branches eligible for security fixes, currently through WordPress 4.7. Those backports were still in progress at announcement time, while 7.1.3 is the current actively maintained release.

What to watch next

  • CVE assignments and severity scoring for the seven issues.
  • Independent technical write-ups clarifying exploit prerequisites for the WXR SQL injection and pending-comment XSS.
  • Completion of security backports for older WordPress branches.
  • Any exploitation telemetry for the newly disclosed flaws.

Still unclear

  • WordPress's release announcement names the flaws but does not yet provide CVE identifiers or full exploit chains for each issue.
  • The announcement says older-branch backports are in progress, so exact fixed versions vary by branch until those releases land.

Sources

Direct reading behind this dossier.

2 sources
WordPress Release Archive
WordPress.org primary documentation

Confirms 7.1.3 as the latest 7.1 release and records concurrent older-branch releases.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment