WordPress has released version 7.1.3, a security and maintenance update that fixes seven security vulnerabilities in WordPress core as well as four additional software bugs. As this is a security release, all WordPress website administrators are advised to install the update as soon as possible.
The release does not focus on new features but instead improves the security and reliability of WordPress. The vulnerabilities addressed include XSS and SQL injection issues, as well as a flaw that could be exploited to cause a denial-of-service (DoS) condition.
What security issues does WordPress 7.1.3 fix?
One of the fixes addresses a stored Cross-Site Scripting (XSS) vulnerability on the Comments administration page that could be exploited through pending comments.
WordPress 7.1.3 also fixes a second-order SQL injection vulnerability related to WXR exports and a problem in the WP_Http::make_absolute_url() method that could be exploited to cause a denial-of-service condition.
Another vulnerability allowed users with the Author role to make posts sticky despite not normally having permission to do so.
The update also addresses an information disclosure issue that could allow unauthenticated users to access comments associated with private or unpublished posts.
In addition, an XSS vulnerability affecting Imgur embeds has been fixed, along with an issue involving forgeable parameters passed to the {status}_{type} hook that could lead to action name collisions.
WordPress 7.1.3 should be installed as soon as possible
WordPress recommends updating websites to version 7.1.3 immediately due to the security fixes included in the release. The update can be installed through the WordPress administration panel under Dashboard → Updates.
Websites with automatic background updates enabled may receive WordPress 7.1.3 automatically. Administrators should nevertheless verify that the update has been successfully installed and that the website continues to function correctly afterwards.
Before performing a manual update, it is also advisable to make sure that a recent and working backup is available, particularly for larger or business-critical WordPress websites.
Where necessary, the security fixes are also being backported to older WordPress branches currently eligible for security updates, going back to WordPress 4.7. However, WordPress notes that only the latest version is actively supported, so running an outdated WordPress version should not be considered a long-term solution.








