WordPress released 7.1.3 on 6 October 2026, a maintenance and security release with seven security fixes and four bug fixes. It is the sixth core security release since 17 July, and the third since 7.1 shipped on 19 August.
What Was Fixed
- Stored cross-site scripting on the Comments admin screen, triggered through pending comments. Reported by Thomas Chauchefoin of Trail of Bits.
- Unauthenticated disclosure of comments on private and unpublished posts. Reported by Ananda Dhakal of Patchstack.
- Second-order SQL injection in the WXR export (Tools → Export). Reported by Anthropic.
- Denial of service in
WP_Http::make_absolute_url(). Reported by Anthropic. - Author-role users able to make posts sticky, which should need a higher role. Reported by Anthropic.
- Cross-site scripting in Imgur embeds. Reported by Zhengyu Liu, Jingcheng Yang and Gavin Zhong.
- Forgeable parameters passed to the
{status}_{type}hook, which can cause action name collisions. Reported by Alex Concha of the WordPress security team.
7.1.3 is the third core security release since July to credit Anthropic, after 7.0.3 (one fix) and 7.1.1 (two). That brings the core vulnerabilities it has reported in that period to six.
WordPress has not yet published severity ratings or CVE numbers for these. As of 8 October, the GitHub security advisories for 7.1.3 are not out. The release post describes only one of the seven, the comment disclosure, as unauthenticated.
Fixes are being backported to every branch back to 4.7. The release post says those backports are still shipping, so sites on an older branch may get their update a little after 7.1.3.
What Our Clients Need to Do
Nothing. 7.1.3 installs through WordPress’s automatic background updates. As with each core security release this year, we check that every site we manage has actually moved to the new version, rather than assuming the update ran.
Sites we keep on an older branch for compatibility get the backport for that branch, and we confirm those the same way once they ship.
Self-Managed Sites
Go to Dashboard → Updates and confirm you are on 7.1.3. If you are on an older branch and no update is offered yet, the backport has not shipped; check again in a day or two.
If you have had to update by hand for each of the six releases since July, check whether core auto-updates are turned off on your site.
For a once-over on whether your site is patched and set up to stay that way, get in touch or see our managed WordPress care plans.