What changed
WordPress released 7.1.3 on October 6 with seven security fixes and four bug fixes. The security set includes stored XSS on the Comments administration page exploitable via pending comments; a denial-of-service issue in WP_Http::make_absolute_url(); second-order SQL injection in WordPress WXR export; an Author-role weakness allowing posts to be made sticky; unauthenticated disclosure of comments on private and unpublished posts; XSS in Imgur embeds; and forgeable parameters passed to the {status}_{type} hook that can cause action-name collision. WordPress says fixes are being backported where necessary to branches eligible for security fixes, currently through 4.7.
Why it matters
This is a broad core-security release rather than a routine maintenance patch. Several issues cross trust boundaries builders commonly rely on: pending comments can reach an administrative XSS surface, private-post comments can be disclosed without authentication, and exported content can carry a second-order SQL-injection path. Operators should update rather than assume the previous 7.1.2 RCE patch left the branch current.
Seven fixes span several trust boundaries
The release touches administrative comment rendering, WXR export, HTTP URL handling, post permissions, private-content comments, embeds and dynamic hook naming. That breadth makes the operational recommendation simple: treat 7.1.3 as a security update, not a discretionary bug-fix release.
Pending comments are part of the attack surface
WordPress specifically says the stored XSS on the Comments administration page is exploitable through pending comments. That matters because content does not need to be publicly approved before it can reach a privileged review surface.
Older branches are receiving backports
WordPress says security fixes are being backported where necessary to branches eligible for security fixes, currently through WordPress 4.7. Those backports were still in progress at announcement time, while 7.1.3 is the current actively maintained release.