WordPress 7.1.3 fixes seven security issues, including comment-related flaws

WordPress 7.1.3 was released on October 6, 2026, with seven security fixes and four bug fixes, making it the second core security update in two weeks after WordPress 7.1.2 addressed a critical security vulnerability on September 22.

What WordPress fixed

AreaIssue fixed in WordPress 7.1.3Reporter named by WordPress
Comments administrationStored XSS on the Comments administration page, exploitable through pending commentsTrail of Bits, in collaboration with OpenAI
HTTP handlingDenial-of-service issue in WP_Http::make_absolute_url()Anthropic
Export toolSecond-order SQL injection in WordPress WXR exportAnthropic
Post permissionsWeakness allowing Author role users to sticky postsAnthropic
Private and unpublished contentUnauthenticated disclosure of comments on private and unpublished postsAnanda Dhakal from Patchstack
EmbedsImgur embeds vulnerable to XSSZhengyu Liu, Jingcheng Yang, and Gavin Zhong
Developer hooksForgeable parameters passed to the {status}_{type} hook that can lead to action name collisionAlex Concha of the WordPress security team

Two of the fixes are especially relevant for sites that accept comments. One addresses unauthenticated disclosure of comments on private and unpublished posts. Another addresses stored XSS on the Comments administration page through pending comments.

XSS on an administration screen is different from a public-page display issue. If an exploit path succeeds, malicious script can be placed in front of a logged-in user with elevated privileges. That makes the pending-comment path worth treating seriously on sites with active public commenting or large moderation queues.

Severity and exposure vary by issue

WordPress did not publish severity scores in its release announcement. WPScan’s public vulnerability database lists one of the seven 7.1.3 items as high severity, four as medium, and two as low.

Patchstack’s analysis separates the fixes by prerequisites. It says two can begin with unauthenticated visitor activity, although the comment-administration XSS case still depends on a moderator or higher-privileged user clicking a crafted link. Other issues require contributor or author access, an administrator export action, or plugin-dependent conditions.

The update remains necessary, but risk depends on site configuration, active features, user roles, and how much untrusted input a site accepts.

Older branches and managed-hosting mitigations

The WordPress Version 7.1.3 documentation says the security fixes are also available in older affected branches as a courtesy, while repeating that only the most recent version of WordPress is actively supported. For long-lived sites parked on older core branches, a branch-specific security backport can reduce exposure, but it does not turn an old branch into a fully supported platform.

Pantheon said it added platform-wide virtual patching through its routing network against external abuse of the stored XSS issue on the Comments administration page, while still telling customers to update to WordPress 7.1.3. That is a useful example of how managed-hosting mitigations can buy time without replacing the core update.

What administrators should check now

WordPress recommends updating immediately. The official release notes say sites that support automatic background updates will begin updating automatically.

  • Confirm that the site is running WordPress 7.1.3, or an applicable branch-specific patched version if the site is intentionally held on an older branch.
  • Check whether automatic background updates completed, especially on sites with custom deployment processes or managed-hosting update controls.
  • For complex or business-critical sites, use the existing staging, backup, or change-control process, but do not leave the security release pending longer than necessary.
  • Review sites with public comments, pending moderation queues, contributor or author accounts, WXR export workflows, Imgur embeds, or custom code that interacts with post statuses and post types.

Related: Is WordPress right for your website? Tech Help Canada looks at costs, SEO, maintenance, flexibility, security considerations, and who the platform is best suited for.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email