WordPress released version 7.1.3 on October 6, 2026. It fixes 7 security flaws and 4 bugs, and the project recommends updating immediately. It concerns every site built on WordPress. Sites with automatic background updates should get it on their own, but it is worth checking that it actually arrived.
What we know
- What shipped and when: WordPress 7.1.3, on October 6, 2026, according to the official WordPress.org announcement by Jake Spurlock, who led the release.
- What is in it: 7 security fixes and 4 bug fixes, according to that announcement. It is a security and maintenance release.
- Who reported the flaws: the announcement credits Trail of Bits, Patchstack, Anthropic, three researchers listed by name and WordPress's own security team. Three of the seven were reported by Anthropic, the AI company behind Claude. The announcement does not say how they were found.
- What the announcement leaves out: there are no CVE identifiers and no severity rating for any of the seven. It does not say any of them is being exploited.
- Older versions: the fixes are also being backported to older branches still eligible for security fixes, currently back to 4.7. The announcement says that work is in progress. On October 6 the WordPress.org release archive already listed 7.0.7, 6.9.10 and 6.8.11, among others.
- Support: WordPress reminds users that only the most recent version is actively supported.
- A busy stretch: this is the third security release on the 7.1 branch in under three weeks. Version 7.1.1 shipped on September 17 with 11 security fixes. Version 7.1.2 followed on September 22 with a fix for a critical vulnerability, according to each release note.
The seven flaws, as WordPress describes them:
- Stored cross-site scripting (XSS) on the Comments screen of the admin area, through pending comments. Reported by Thomas Chauchefoin at Trail of Bits.
- A denial-of-service issue in an internal method of the HTTP request class. Reported by Anthropic.
- A second-order SQL injection in the WXR content export. Reported by Anthropic.
- A weakness that let users with the Author role make posts sticky. Reported by Anthropic.
- Comments on private and unpublished posts that could be read without logging in. Reported by Ananda Dhakal from Patchstack.
- XSS in Imgur embeds. Reported by Zhengyu Liu, Jingcheng Yang and Gavin Zhong.
- Forgeable parameters passed to an internal hook, which could lead to an action name collision. Reported by Alex Concha of the WordPress security team.
What changes and what doesn't
What changes: a WordPress site that is not on 7.1.3, or on the patched release of its own branch, now has public flaws with a fix available. Since October 6 the list is there for everyone to read, including anyone scanning for sites that have not been updated.
What doesn't change: the look and the features of your site. This is not a feature release. It does not fix plugins or themes either. Those are updated separately.
Several of the flaws need specific conditions, going by their own descriptions. One needs an account with the Author role. One sits in the content export. One goes through pending comments. A site with comments turned off and a single user looks less exposed than a blog with several authors. That reading is this article's: the announcement makes no such distinction and tells everyone to update.
How to tell if it affects you
It affects you if your website, blog or online store runs on WordPress. Seven steps:
- Check your version. Log in to the admin area and open "Dashboard → Updates". It shows the version you run and whether a newer one is available.
- If it already says 7.1.3, the automatic update did its job. WordPress usually applies minor releases on its own, but some hosts and some configurations turn that off.
- If it has not arrived, back up your files and your database first. Then update from that same screen.
- If you have comments awaiting moderation, update before you open them, as a precaution: one of the flaws goes through that screen.
- If you are still on an older branch (7.0, 6.9 or earlier), install the patched release for your branch and plan the move to 7.1. WordPress describes those backports as a courtesy, not as support.
- If your hosting is managed or someone else maintains the site, ask: "Is my WordPress on 7.1.3 yet?"
- After updating, test the home page, the forms, the comments and the checkout. Then review who holds the Author role or higher, and remove the accounts nobody uses anymore.
Related: Apache 2.4.69 Fixes 20 Flaws: How to Check Your Server
Sources
- WordPress.org, "WordPress 7.1.3 Maintenance and Security Release", October 6, 2026
- WordPress.org, release archive
- WordPress.org, "WordPress 7.1.2 Release", September 22, 2026
- WordPress.org, "WordPress 7.1.1 Maintenance and Security Release", September 17, 2026
Updates: this note will be extended if WordPress publishes CVE identifiers or a severity rating for any of the flaws, or if exploitation is confirmed.