Skip to main content
SecurityOctober 8, 20263 min read

WordPress 7.1.3 Fixes a Stored XSS in the Comments Screen

Get technical support

Which of these can actually be exploited?

WordPress 7.1.3, released October 6, 2026, fixes seven security issues, among them a stored XSS on the Comments screen that a pending comment can trigger. Most sites update themselves, but sites that cannot write their own files need a manual update.

What 7.1.3 Fixes

WordPress 7.1.3 was released on October 6, 2026 with seven security fixes and four bug fixes, and the WordPress team recommends updating immediately. The security fixes cover:

  • a stored cross-site scripting (XSS) issue on the Comments administration page, exploitable through pending comments
  • cross-site scripting through Imgur embeds
  • a second-order SQL injection in the WXR export
  • unauthenticated disclosure of comments on private and unpublished posts
  • a denial of service in the WP_Http::make_absolute_url() method
  • a weakness that let users with the Author role make posts sticky
  • forgeable parameters passed to the {status}_{type} hook, which could lead to action name collisions

The release post does not rate them or list CVE numbers.

Why the Comments Fix Matters Most

A stored XSS is saved with the content and runs later in the browser of whoever views it. Here the content is a comment waiting for moderation, and it runs on the Comments screen, which is exactly where an administrator or editor goes to review such comments. Script running in that session acts with that person's permissions. Sites that accept comments should not leave this update for the next maintenance window.

Will Your Site Update Itself?

Most sites will. WordPress installs minor and security releases in the background where it can, and the release post confirms that the update starts on its own on those sites. To confirm, look under Dashboard, then Updates, or run wp core version with WP-CLI.

Some sites need a manual step:

  • the web server cannot write to the WordPress files
  • WordPress runs from a container image, which only changes with a new build
  • core is installed with Composer, as in Bedrock, so it updates with your dependencies
  • automatic updates were switched off, for example with the WP_AUTO_UPDATE_CORE constant

On these, update to 7.1.3 and then check the version on the live site, not only in the repository.

Older Branches

The security fixes are being backported to every branch that is still eligible, currently back to 4.7, and each backport ships when it is ready. Only the latest version is actively supported, so a site on an old branch should plan its move to 7.1 rather than count on backports.

Where It Fits

For a recent example of what a flaw in WordPress core can expose, see our write-up of wp2shell. Keeping core, plugins and themes current on every site you run is part of our security and compliance work.

Sources

Or read how we handle it in Security & Compliance.