WordPress 7.1.3 Maintenance and Security Release: Update Your Site Now

WordPress has just rolled out version 7.1.3, and it’s an important one. This is a maintenance and security release, which means it focuses on keeping your site safe and running smoothly. In total, it includes 7 security fixes and 4 bug fixes.

Because this update addresses security issues, the WordPress team strongly recommends that you update your site right away. The sooner you update, the safer your site will be.

How to Update

Updating is simple. You can:

Download WordPress 7.1.3 directly from WordPress.org

Or log in to your WordPress Dashboard, click on “Updates,” and then click “Update Now”

If your site supports automatic background updates, the update will start on its own—no action needed from you.

What’s Fixed in This Release?

This release patches several security vulnerabilities. Here’s a quick look at what was fixed and who reported each issue:

  • A stored XSS on the Comments administration page, which could be triggered through pending comments — reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method — reported by Anthropic
  • A second-order SQL injection in the WordPress WXR export — reported by Anthropic
  • A weakness that allowed Author role users to sticky posts — reported by Anthropic
  • Unauthenticated disclosure of comments on private and unpublished posts — reported by Ananda Dhakal from Patchstack
  • Imgur embeds vulnerable to XSS — reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook, which could lead to action name collision — reported by Alex Concha of the WordPress security team

Thanks to the Contributors

The WordPress team extends a big thank you to everyone who responsibly reported the issues, helping make WordPress safer for everyone.

This release was led by Jake Spurlock, and it wouldn’t have been possible without the hard work of 34 contributors.

Their teamwork and coordination behind the scenes show just how strong and capable the WordPress community really is.

Backports for Older Versions

As a courtesy, the security fixes are also being backported to older branches that still receive security updates, currently down to version 4.7.

These backports are in progress and will be released as they become ready.

Just remember: only the most recent version of WordPress is actively supported. So if you’re running an older version, it’s a good idea to upgrade soon.

Stay Up to Date

WordPress 7.1.3 is a release you don’t want to skip. It fixes important security issues and helps keep your site protected.

Whether you update manually or let it happen automatically, make sure your site gets this update as soon as possible.

Stay safe, and keep your WordPress site up to date!

Mehraz Morshed Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *