WordPress 7.1.3, released October 6, 2026, fixes seven security issues, among them a stored XSS on the Comments screen that a pending comment can trigger. Most sites update themselves, but sites that cannot write their own files need a manual update.
What 7.1.3 Fixes
WordPress 7.1.3 was released on October 6, 2026 with seven security fixes and four bug fixes, and the WordPress team recommends updating immediately. The security fixes cover:
- a stored cross-site scripting (XSS) issue on the Comments administration page, exploitable through pending comments
- cross-site scripting through Imgur embeds
- a second-order SQL injection in the WXR export
- unauthenticated disclosure of comments on private and unpublished posts
- a denial of service in the
WP_Http::make_absolute_url()method - a weakness that let users with the Author role make posts sticky
- forgeable parameters passed to the
{status}_{type}hook, which could lead to action name collisions
The release post does not rate them or list CVE numbers.
Why the Comments Fix Matters Most
A stored XSS is saved with the content and runs later in the browser of whoever views it. Here the content is a comment waiting for moderation, and it runs on the Comments screen, which is exactly where an administrator or editor goes to review such comments. Script running in that session acts with that person's permissions. Sites that accept comments should not leave this update for the next maintenance window.
Will Your Site Update Itself?
Most sites will. WordPress installs minor and security releases in the background where it can, and the release post confirms that the update starts on its own on those sites. To confirm, look under Dashboard, then Updates, or run wp core version with WP-CLI.
Some sites need a manual step:
- the web server cannot write to the WordPress files
- WordPress runs from a container image, which only changes with a new build
- core is installed with Composer, as in Bedrock, so it updates with your dependencies
- automatic updates were switched off, for example with the
WP_AUTO_UPDATE_COREconstant
On these, update to 7.1.3 and then check the version on the live site, not only in the repository.
Older Branches
The security fixes are being backported to every branch that is still eligible, currently back to 4.7, and each backport ships when it is ready. Only the latest version is actively supported, so a site on an old branch should plan its move to 7.1 rather than count on backports.
Where It Fits
For a recent example of what a flaw in WordPress core can expose, see our write-up of wp2shell. Keeping core, plugins and themes current on every site you run is part of our security and compliance work.
Sources
Or read how we handle it in Security & Compliance.
Related News
WordPress 6.9.2 Security Release Is Now Available
WordPress 6.9.2 shipped as a March 2026 security release, making it the safer reference point than older 6.8-focused update coverage.
SecurityOpenSSL 3.0 Stops Getting Security Fixes in September and You Probably Still Ship It
OpenSSL 3.0 stops receiving all fixes, including security fixes, after September 7, 2026, and the 3.4 line follows on October 22. For most teams the distro backports cover it, but self-compiled, vendored, and container-bundled OpenSSL go quietly unpatched. Here is who is actually exposed and how to check.
SecurityMay 2026 Linux and cPanel CVE Storm: What to Patch Now
Three high-severity Linux kernel CVEs and a critical cPanel authentication bypass are being actively exploited in May 2026. Here is what to patch and how.