WordPress 7.1.3 landed on 6 October 2026. It’s a maintenance and security release with seven security fixes and four bug fixes. Two weeks ago, 7.1.2 fixed a single vulnerability (CVE-2026-87902) that allowed an unauthenticated visitor to trigger a local file inclusion and, under the right PHP configuration, could lead to remote code execution. 7.1.3 is a different kind of release. Two fixes start with an unauthenticated visitor: the comment-feed leak, and the comments XSS, which also needs a moderator to click. Three need a Contributor or Author account, one needs an administrator to run an export, and one is plugin-dependent hardening. Update as soon as you can, but this isn’t a drop-everything emergency.
| Vulnerability Patched | Requirements | Reported By |
| Stored XSS on the Comments admin page, via pending comments | A pending comment and a moderator (Editor+) clicks a link in it | Thomas Chauchefoin, Trail of Bits |
Denial of service in WP_Http::make_absolute_url() | A Contributor+ account | Anthropic |
| Second-order SQL injection in WXR export | An administrator running an export, plus a bad _thumbnail_id value already in the database | Anthropic |
| Authors can sticky posts | An Author+ account | Anthropic |
| Disclosure of comments on private and unpublished posts | Nothing (Unauthenticated) | Ananda Dhakal, Patchstack |
| Imgur embeds vulnerable to XSS | A Contributor+ account, and a target to view it | Zhengyu Liu, Jingcheng Yang, Gavin Zhong |
{status}_{type} hook name collision | A plugin that passes a raw status or post type into wp_insert_post() | Alex Concha, WordPress Security Team |
What the Code Shows
Comments XSS
The Help tab click handler in wp-admin/js/common.js passed a link’s href to jQuery’s $(), which builds HTML from any string that looks like HTML. A link inside a pending comment can carry such an href. The handler only listens inside elements with the class contextual-help-tabs, so the link also needs a wrapper with that class. Visitor comments couldn’t carry a class before 7.1.0, which added span class support for note mentions and trims it down on save. Per our review, the pending-comment attack affects 7.1.0-7.1.2. The older backports harden the same code. 7.1.3 uses .find(), which only reads selectors.

make_absolute_url() DoS
A loop that collapses segment/../ pairs never exits on a relative path like a//../b, because its regex matches nothing and the path never changes. In WordPress, a Contributor can trigger it through the block editor’s link preview by pointing it at a page they control. 7.1.3 breaks the loop when a pass replaces nothing.

WXR Export SQL Injection
The export collected featured-image IDs straight from _thumbnail_id metadata and concatenated them into a query string without ensuring the ID was an integer. 7.1.3 adds absint() at three points. The vulnerable code only exists since 6.5.0, and is only reached when exporting a single content type; the default “All content” export doesn’t touch it.

Author Sticky Posts
The REST API refused a sticky request only when the user lacked both edit_others_posts and publish_posts capabilities. Authors have the publish_posts capability, so they passed. The fix flips && (and) to || (or).

Private Post Comments
For single-post comment feeds, WP_Query loaded the post’s comments before checking whether a visitor could see the post. The check then cleared the post but not the comments, and feeds never return a 404, so the feed printed them. 7.1.3 moves the comment query after the visibility check.
Imgur XSS
WordPress runs HTML from untrusted oEmbed providers through a filter that reduces it to a sandboxed iframe. Imgur sat on the trusted list, which skips that filter, so whatever came back from Imgur’s API was output directly. That response includes text from the uploader’s own image or album, so anything attacker-controlled in it landed on the page unfiltered. The fix removes Imgur as a trusted provider, so Imgur URLs are no longer embedded unfiltered.

Note: While WordPress 7.1.3 patches this vulnerability, it does not remove any existing, cached oEmbed content (the _oembed_* post meta, and oembed_cache posts), so an existing malicious embed keeps rendering. Ensure you’ve cleared your site’s cache after updating.
Hook Collision
WordPress builds some action names out of a post’s own data. When a post changes status, wp_transition_post_status() fires ${new_status}_{$post_type}, so publishing a post fires publish_post. The catch is that unrelated actions follow the same naming pattern: delete_post fires when a post is deleted, and comment_post fires when a comment is added.
7.1.2 never checked that the status and post type were registered before building the name. A post saved with the status delete and the type post fired delete_post, the same action as a real deletion, and ever callback hooked to it ran as if a post had just been deleted. 7.1.3 only fires these hooks when the status and post type are registered.
Timeline
Update Now
WordPress 7.1.3 is available from the Dashboard under Updates, or from WordPress.org. Sites with automatic background updates will pick it up on their own. These fixes have been backported to older branches, through at least 6.6.
While you’re in the Dashboard to update, audit who holds Contributor or higher roles on your sites. Many of these fixes are about what those roles can reach.


