Summary
- WordPress 7.1.3 contains seven security fixes and four maintenance fixes.
- Weaknesses include stored XSS, SQL injection and private-comment disclosure.
- WordPress recommends immediate updating and supports automatic background deployment.
WordPress has released version 7.1.3 with fixes for seven security vulnerabilities, including stored cross-site scripting, second-order SQL injection and unauthenticated disclosure of comments associated with private or unpublished posts.
The 6 October update also contains four maintenance fixes, and the WordPress project recommends that sites move to the corrected release immediately. Installations configured for automatic background updates can receive the version without an administrator manually initiating the change.
Several of the weaknesses affect different parts of the publishing workflow rather than forming one attack chain. A stored cross-site scripting flaw can be triggered through pending comments displayed within the administration area, meaning attacker-controlled content may later be processed in a more privileged context.
Another cross-site scripting issue involves Imgur embeds, while a separate weakness in the WordPress WXR export mechanism can lead to second-order SQL injection. In that type of flaw, malicious input can initially be stored without causing an immediate effect before becoming dangerous when another component later processes it.
Unauthenticated users could also gain access to comments attached to private or unpublished posts under one of the corrected conditions. The underlying post content is separate, but comments can contain unpublished information, internal context or discussion that was not intended for public access.
Other fixes address the ability of users holding the Author role to make posts sticky when they should not be able to do so, alongside a denial-of-service weakness involving WordPress HTTP functionality and problems affecting the handling of status and content-type parameters.
The variety of outcomes reflects the breadth of the core WordPress platform. Public content submission, administrative interfaces, export tools, permissions and remote content handling all operate inside the same application, so weaknesses in one function can expose information or privileged users even when they do not lead directly to server compromise.
WordPress’s deployment scale also changes the operational consequence of a core security release. Individual sites vary widely in configuration and exposure, but organisations running several installations may need to coordinate updates across publishing teams, development environments and hosting providers rather than treating the release as an isolated desktop-style patch.
The project’s release archive identifies 7.1.3 as the latest maintained release in the 7.1 series. Earlier 7.1 releases have received their own security updates, including version 7.1.1 in September, but the seven vulnerabilities fixed this week are a separate set rather than revisions to that earlier issue.
Core updates also cover only one layer of a typical WordPress estate. Themes and plugins follow their own maintenance cycles and can introduce separate vulnerabilities, leaving organisations dependent on the security practices of multiple developers even after the core platform is current.
Automatic background updates can shorten the period during which a site remains exposed to a known WordPress core vulnerability, although some organisations disable automated deployment because changes must first pass compatibility or production testing. Those environments will need to move 7.1.3 through their established release process.
With seven security fixes landing together, the update spans information disclosure, code injection and availability rather than one dominant vulnerability. The relevant exposure for any installation depends on the enabled functions, accepted content, user roles and exact version being operated.




