📣 Send us your press release
Site updates every 15 minutes
Technology

WordPress 7.1.3 Released, Fixing Seven Security Vulnerabilities

WordPress released version 7.1.3 yesterday, addressing seven security vulnerabilities and four software bugs. Three of the reported vulnerabilities were identified by the AI company Anthropic.

7 October 2026

WordPress released version 7.1.3 on October 6, patching seven security vulnerabilities and resolving four software bugs within its platform. This update is crucial for maintaining the security of the widely used content management system.

Of the seven vulnerabilities fixed, three were reported by the artificial intelligence company Anthropic. Trail of Bits and Patchstack each reported one vulnerability, with another found by three independent researchers and the final one discovered by the WordPress security team.

The most easily exploitable vulnerability was located in the comment administration interface, classified as a stored cross-site scripting (XSS) issue. Reported by Thomas Chauchefoin of Trail of Bits, malicious scripts could be triggered when an administrator accessed the page, lying dormant in the moderation queue.

Among the three vulnerabilities reported by Anthropic, one existed in the WXR exporter. In this case, attacker input was stored and only posed a threat when a user performed a content export and the system reused the input to construct a database query. Other issues addressed included a denial-of-service vulnerability in the WP_Http::make_absolute_url() method and a privilege escalation problem allowing author-role users to improperly mark posts as sticky.

Original source: ithome.com