Start trial

WordPress 7.1.3 Security Release

WordPress 7.1.3 landed on 6 October 2026. It’s a maintenance and security release with seven security fixes and four bug fixes. Two weeks ago, 7.1.2 fixed a sin

PublishedOctober 6, 2026
Chazz Wolcott avatar
Chazz Wolcott
Security Researcher at Patchstack

WordPress 7.1.3 landed on 6 October 2026. It’s a maintenance and security release with seven security fixes and four bug fixes. Two weeks ago, 7.1.2 fixed a single vulnerability (CVE-2026-87902) that allowed an unauthenticated visitor to trigger a local file inclusion and, under the right PHP configuration, could lead to remote code execution. 7.1.3 is a different kind of release. Two fixes start with an unauthenticated visitor: the comment-feed leak, and the comments XSS, which also needs a moderator to click. Three need a Contributor or Author account, one needs an administrator to run an export, and one is plugin-dependent hardening. Update as soon as you can, but this isn’t a drop-everything emergency.

Vulnerability PatchedRequirementsReported By
Stored XSS on the Comments admin page, via pending commentsA pending comment and a moderator (Editor+) clicks a link in itThomas Chauchefoin, Trail of Bits
Denial of service in WP_Http::make_absolute_url()A Contributor+ accountAnthropic
Second-order SQL injection in WXR exportAn administrator running an export, plus a bad _thumbnail_id value already in the databaseAnthropic
Authors can sticky postsAn Author+ accountAnthropic
Disclosure of comments on private and unpublished postsNothing (Unauthenticated)Ananda Dhakal, Patchstack
Imgur embeds vulnerable to XSSA Contributor+ account, and a target to view itZhengyu Liu, Jingcheng Yang, Gavin Zhong
{status}_{type} hook name collisionA plugin that passes a raw status or post type into wp_insert_post()Alex Concha, WordPress Security Team

What the Code Shows

Comments XSS

The Help tab click handler in wp-admin/js/common.js passed a link’s href to jQuery’s $(), which builds HTML from any string that looks like HTML. A link inside a pending comment can carry such an href. The handler only listens inside elements with the class contextual-help-tabs, so the link also needs a wrapper with that class. Visitor comments couldn’t carry a class before 7.1.0, which added span class support for note mentions and trims it down on save. Per our review, the pending-comment attack affects 7.1.0-7.1.2. The older backports harden the same code. 7.1.3 uses .find(), which only reads selectors.

A screenshot of the diff for wp-admin/js/common.js from GitHub.

make_absolute_url() DoS

A loop that collapses segment/../ pairs never exits on a relative path like a//../b, because its regex matches nothing and the path never changes. In WordPress, a Contributor can trigger it through the block editor’s link preview by pointing it at a page they control. 7.1.3 breaks the loop when a pass replaces nothing.

A screenshot of the diff for wp-includes/class-wp-http.php from GitHub.

WXR Export SQL Injection

The export collected featured-image IDs straight from _thumbnail_id metadata and concatenated them into a query string without ensuring the ID was an integer. 7.1.3 adds absint() at three points. The vulnerable code only exists since 6.5.0, and is only reached when exporting a single content type; the default “All content” export doesn’t touch it.

A screenshot of the diff for wp-admin/includes/export.php from GitHub.

Author Sticky Posts

The REST API refused a sticky request only when the user lacked both edit_others_posts and publish_posts capabilities. Authors have the publish_posts capability, so they passed. The fix flips && (and) to || (or).

A screenshot of the diff for wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php from GitHub.

Private Post Comments

For single-post comment feeds, WP_Query loaded the post’s comments before checking whether a visitor could see the post. The check then cleared the post but not the comments, and feeds never return a 404, so the feed printed them. 7.1.3 moves the comment query after the visibility check.

Imgur XSS

WordPress runs HTML from untrusted oEmbed providers through a filter that reduces it to a sandboxed iframe. Imgur sat on the trusted list, which skips that filter, so whatever came back from Imgur’s API was output directly. That response includes text from the uploader’s own image or album, so anything attacker-controlled in it landed on the page unfiltered. The fix removes Imgur as a trusted provider, so Imgur URLs are no longer embedded unfiltered.

Note: While WordPress 7.1.3 patches this vulnerability, it does not remove any existing, cached oEmbed content (the _oembed_* post meta, and oembed_cache posts), so an existing malicious embed keeps rendering. Ensure you’ve cleared your site’s cache after updating.

Hook Collision

WordPress builds some action names out of a post’s own data. When a post changes status, wp_transition_post_status() fires ${new_status}_{$post_type}, so publishing a post fires publish_post. The catch is that unrelated actions follow the same naming pattern: delete_post fires when a post is deleted, and comment_post fires when a comment is added.

7.1.2 never checked that the status and post type were registered before building the name. A post saved with the status delete and the type post fired delete_post, the same action as a real deletion, and ever callback hooked to it ran as if a post had just been deleted. 7.1.3 only fires these hooks when the status and post type are registered.

Timeline

6 October 2026WordPress 7.1.3 released, with backports through the 6.6 releases. At the time of this article’s publication, branches 4.7-6.5 are yet to be patched.
6 October 2026Published vulnerabilities added to the Patchstack Database.

Update Now

WordPress 7.1.3 is available from the Dashboard under Updates, or from WordPress.org. Sites with automatic background updates will pick it up on their own. These fixes have been backported to older branches, through at least 6.6.

While you’re in the Dashboard to update, audit who holds Contributor or higher roles on your sites. Many of these fixes are about what those roles can reach.

Like it? Share it.

Related articles