WordPress 7.1.3 has been released with seven security fixes and four bug fixes, addressing vulnerabilities such as stored cross-site scripting (XSS), a denial-of-service (DoS) issue, a second-order SQL injection, and the unauthorized disclosure of comments on private and unpublished posts.
The security fixes are being backported to supported WordPress branches through version 4.7, with the backports shipping as they become ready.
Breaking down the seven security fixes
Patchstack has provided a detailed analysis of the seven security issues addressed in WordPress 7.1.3.
The disclosure of comments on private and unpublished posts can be triggered without authentication, and Ananda Dhakal from Patchstack reported the vulnerability. According to the analysis, WordPress retrieved comments before checking whether the visitor was permitted to view the post. The post was then removed from the response when access was denied, but its comments remained. WordPress 7.1.3 moves the comment query until after the visibility check.
The stored cross-site scripting (XSS) vulnerability on the Comments administration page was reported by Thomas Chauchefoin of Trail of Bits. Exploiting the issue requires a pending comment and a moderator with Editor-level access or higher to click a link in it. The vulnerability affects WordPress 7.1.0 through 7.1.2, according to Patchstack. WordPress 7.1.3 changes the affected code to use .find(), which only reads selectors.
Three of the vulnerabilities were reported by Anthropic, covering a denial-of-service issue, a weakness that allowed Authors to make posts sticky, and a second-order SQL injection in WXR export.
The denial-of-service vulnerability in WP_Http::make_absolute_url() that requires a Contributor-level account or higher. The issue can occur when the function processes a relative path that does not change as it is processed. A Contributor can trigger it through the block editor’s link preview by pointing the preview at a page they control. WordPress 7.1.3 stops the processing loop when it makes no change.
The second Anthropic-reported issue allowed Authors to make posts sticky, and an Author-level account or higher is required to exploit the issue. The existing capability check allowed Authors to pass because they have the publish_posts capability. WordPress 7.1.3 changes the check to prevent this.
The third issue reported is a second-order SQL injection in WXR export, and the issue requires an administrator to run an export and a malicious _thumbnail_id value to already exist in the database. The vulnerable code used the value stored in _thumbnail_id when building the export query without first ensuring it was an integer. WordPress 7.1.3 adds integer conversion at three points. The affected code was introduced in WordPress 6.5.0 and is reached when exporting a single content type.
The XSS vulnerability involving Imgur embeds was reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong. It requires a Contributor-level account or higher and a target to view the affected content. Imgur was included among WordPress’s trusted oEmbed providers, allowing content returned by its API to bypass the filtering applied to untrusted providers. The update removes Imgur from the trusted list.
Existing cached Imgur oEmbed content is not removed by the update. Patchstack notes that malicious content already stored in _oembed_* post metadata or oembed_cache posts can therefore continue to render. Sites should clear their cache after updating.
The final vulnerability involves a {status}_{type} hook name collision and was reported by Alex Concha of the WordPress security team. It requires a plugin that passes a raw status or post type into wp_insert_post(). Under certain conditions, this could cause WordPress to trigger an action name associated with a different operation. WordPress 7.1.3 limits these hooks to registered post statuses and post types.
The release also includes four bug fixes, addressing an issue with site icons, removing someecards.com as an oEmbed provider, updating the reverbnation.com oEmbed endpoint, and fixing a fatal error that could occur when uploading an image without the DOM library installed.
The latest in a series of WordPress security releases
WordPress 7.1.3 follows several security-focused releases in recent months. Version 7.1.2 arrived on September 22, 2026, with a patch for a critical unauthenticated path traversal vulnerability. It was preceded by WordPress 7.1.1 on September 17, which included 11 security fixes. Earlier releases included version 7.0.4 on August 12, which addressed a remote code execution vulnerability, and 7.0.3 on August 6, with 12 security fixes. WordPress 7.0.2, released on July 17, addressed a critical pre-authentication remote code execution vulnerability as well as a high-severity SQL injection vulnerability.
John Blackbourn, Director of WordPress Security at Human Made, recently explained what happens behind the scenes between a vulnerability report and a WordPress security release.
The WordPress HackerOne program has paid more than $200,000 in total bounties, with $90,000 to $95,000 paid over the past 90 days. The program received 2,004 reports during the same period.