WordPress 7.1.3 Fixes SQL Injection, Stored XSS Flaws

Three of the seven flaws, including a second-order SQL injection in the WXR exporter, were reported by AI company Anthropic.

By Vivek • • 3 Min Read • 0 • Follow on Google News Add to Preferred Source
Security Release

On Tuesday, WordPress released version 7.1.3, a security and maintenance update that patches seven vulnerabilities in the platform’s core and fixes four bugs.

The release announcement credits AI company Anthropic with three of the seven reports. Trail of Bits and Patchstack get one each, a team of three independent researchers gets one, and WordPress’s own security team gets the last. WordPress has not published CVE identifiers or severity scores for any of the flaws, and it describes each one in a single line.

The flaw with the clearest path to an administrator account is a stored cross-site scripting (XSS) bug on the Comments administration screen, reported by Thomas Chauchefoin of Trail of Bits. In a stored XSS attack, a malicious script is saved on the site and runs later in someone else’s browser. Here, the entry point is a pending comment. The script would sit in the moderation queue and run when a moderator, often an administrator, opens that page.

Anthropic’s reports include a second-order SQL injection in the WXR exporter, the tool WordPress uses to export posts, comments, and other content as an XML file. In a second-order injection, the attacker’s input is first stored without causing harm. It becomes an attack only when the application reuses it in a later database query, which, in this case, occurs when someone runs an export.

The company also reported a denial-of-service bug in WP_Http::make_absolute_url(), the method WordPress’s HTTP layer uses to turn a relative link into a full URL. Its third report was a permissions issue that allowed users with the Author role to mark posts as sticky, pinning them to the top of the blog’s front page. WordPress normally reserves that action for Editors and higher roles.

Ananda Dhakal of Patchstack found that comments on private and unpublished posts could be read by visitors who were not logged in. Zhengyu Liu, Jingcheng Yang, and Gavin Zhong reported an XSS flaw in WordPress’s Imgur embeds, the handler that turns a pasted Imgur link into an embedded image.

The seventh fix, credited to Alex Concha of the WordPress security team, covers the dynamic {status}_{type} hook. WordPress builds this hook’s name from a post’s status and type, for example publish_post. Some of the parameters that go into that name could be forged, so the resulting name could match a different, unrelated action.

Version 7.1.3 is WordPress’s fifth security release since early August. Version 7.1.1 shipped on September 17 with 11 fixes, two of them also reported by Anthropic. Five days later, version 7.1.2 patched CVE-2026-87902, an unauthenticated path traversal flaw in page template resolution, which Patchstack later saw attackers abusing.

WordPress made no mention of attacks exploiting the flaws fixed in 7.1.3.

Sites with automatic background updates enabled will install 7.1.3 on their own. Administrators can also update from the Updates screen in the Dashboard or download the release directly.

WordPress said it is backporting the fixes to every branch still eligible for security updates, which currently goes back to 4.7. Those backports are still in progress and will ship as each one is ready, so sites on older branches may not be protected yet. “Only the most recent version of WordPress is actively supported,” the project said.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all