# WordPress 7.1.3 patches seven core security flaws — including pending-comment XSS and WXR SQL injection

WordPress 7.1.3 fixes seven core security issues across comments, exports, embeds, HTTP handling and permissions, with security backports in progress for older eligible branches.

The October 6 release is broader than WordPress 7.1.2's single critical RCE fix: it closes seven separate core flaws, including stored XSS through pending comments, second-order SQL injection in WXR exports and unauthenticated disclosure of comments on private posts.

- Status: Active
- Published: 2026-10-07T14:14:13+13:00
- Updated: 2026-10-07T14:14:13+13:00
- Categories: Web Development, WordPress
- Tags: security, SQL injection, WordPress 7.1.3, XSS
- Canonical HTML: https://beyondthe.news/dossiers/wordpress-7-1-3-security-pending-comment-xss-wxr-sql-injection

## What changed

WordPress released 7.1.3 on October 6 with seven security fixes and four bug fixes. The security set includes stored XSS on the Comments administration page exploitable via pending comments; a denial-of-service issue in WP_Http::make_absolute_url(); second-order SQL injection in WordPress WXR export; an Author-role weakness allowing posts to be made sticky; unauthenticated disclosure of comments on private and unpublished posts; XSS in Imgur embeds; and forgeable parameters passed to the {status}_{type} hook that can cause action-name collision. WordPress says fixes are being backported where necessary to branches eligible for security fixes, currently through 4.7.

## Why it matters

This is a broad core-security release rather than a routine maintenance patch. Several issues cross trust boundaries builders commonly rely on: pending comments can reach an administrative XSS surface, private-post comments can be disclosed without authentication, and exported content can carry a second-order SQL-injection path. Operators should update rather than assume the previous 7.1.2 RCE patch left the branch current.

## Seven fixes span several trust boundaries

The release touches administrative comment rendering, WXR export, HTTP URL handling, post permissions, private-content comments, embeds and dynamic hook naming. That breadth makes the operational recommendation simple: treat 7.1.3 as a security update, not a discretionary bug-fix release.

## Pending comments are part of the attack surface

WordPress specifically says the stored XSS on the Comments administration page is exploitable through pending comments. That matters because content does not need to be publicly approved before it can reach a privileged review surface.

## Older branches are receiving backports

WordPress says security fixes are being backported where necessary to branches eligible for security fixes, currently through WordPress 4.7. Those backports were still in progress at announcement time, while 7.1.3 is the current actively maintained release.

## Key details

- WordPress 7.1.3 was released October 6, 2026.
- It contains seven security fixes and four bug fixes.
- The security fixes include stored XSS via pending comments and second-order SQL injection in WXR export.
- Another fix addresses unauthenticated disclosure of comments on private and unpublished posts.
- WordPress recommends updating immediately and says eligible older branches are receiving backports where necessary.

## Builder takeaways

- Update production sites to 7.1.3 rather than treating 7.1.2 as the current secure endpoint.
- Include pending-comment moderation screens in privileged XSS threat modelling.
- If workflows import or export WXR files, treat exported/imported content as untrusted data even when the dangerous effect is delayed.
- Track older-branch backports separately if an installation cannot yet move to 7.1.3.

## What to watch

- CVE assignments and severity scoring for the seven issues.
- Independent technical write-ups clarifying exploit prerequisites for the WXR SQL injection and pending-comment XSS.
- Completion of security backports for older WordPress branches.
- Any exploitation telemetry for the newly disclosed flaws.

## Uncertainties

- WordPress's release announcement names the flaws but does not yet provide CVE identifiers or full exploit chains for each issue.
- The announcement says older-branch backports are in progress, so exact fixed versions vary by branch until those releases land.

## Sources

- [WordPress 7.1.3 Maintenance and Security Release](https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/) — WordPress.org · primary · 2026-10-06T00:00:00+13:00. Primary release announcement listing all seven security fixes and backport status.
- [WordPress Release Archive](https://wordpress.org/download/releases/) — WordPress.org · primary documentation · 2026-10-06T00:00:00+13:00. Confirms 7.1.3 as the latest 7.1 release and records concurrent older-branch releases.

