WordPress 7.1.3 was released on October 6, 2026, with seven security fixes and four bug fixes, making it the second core security update in two weeks after WordPress 7.1.2 addressed a critical security vulnerability on September 22.
What WordPress fixed
| Area | Issue fixed in WordPress 7.1.3 | Reporter named by WordPress |
|---|---|---|
| Comments administration | Stored XSS on the Comments administration page, exploitable through pending comments | Trail of Bits, in collaboration with OpenAI |
| HTTP handling | Denial-of-service issue in WP_Http::make_absolute_url() | Anthropic |
| Export tool | Second-order SQL injection in WordPress WXR export | Anthropic |
| Post permissions | Weakness allowing Author role users to sticky posts | Anthropic |
| Private and unpublished content | Unauthenticated disclosure of comments on private and unpublished posts | Ananda Dhakal from Patchstack |
| Embeds | Imgur embeds vulnerable to XSS | Zhengyu Liu, Jingcheng Yang, and Gavin Zhong |
| Developer hooks | Forgeable parameters passed to the {status}_{type} hook that can lead to action name collision | Alex Concha of the WordPress security team |
The comment-related fixes stand out
Two of the fixes are especially relevant for sites that accept comments. One addresses unauthenticated disclosure of comments on private and unpublished posts. Another addresses stored XSS on the Comments administration page through pending comments.
XSS on an administration screen is different from a public-page display issue. If an exploit path succeeds, malicious script can be placed in front of a logged-in user with elevated privileges. That makes the pending-comment path worth treating seriously on sites with active public commenting or large moderation queues.
Severity and exposure vary by issue
WordPress did not publish severity scores in its release announcement. WPScan’s public vulnerability database lists one of the seven 7.1.3 items as high severity, four as medium, and two as low.
Patchstack’s analysis separates the fixes by prerequisites. It says two can begin with unauthenticated visitor activity, although the comment-administration XSS case still depends on a moderator or higher-privileged user clicking a crafted link. Other issues require contributor or author access, an administrator export action, or plugin-dependent conditions.
The update remains necessary, but risk depends on site configuration, active features, user roles, and how much untrusted input a site accepts.
Older branches and managed-hosting mitigations
The WordPress Version 7.1.3 documentation says the security fixes are also available in older affected branches as a courtesy, while repeating that only the most recent version of WordPress is actively supported. For long-lived sites parked on older core branches, a branch-specific security backport can reduce exposure, but it does not turn an old branch into a fully supported platform.
Pantheon said it added platform-wide virtual patching through its routing network against external abuse of the stored XSS issue on the Comments administration page, while still telling customers to update to WordPress 7.1.3. That is a useful example of how managed-hosting mitigations can buy time without replacing the core update.
What administrators should check now
WordPress recommends updating immediately. The official release notes say sites that support automatic background updates will begin updating automatically.
- Confirm that the site is running WordPress 7.1.3, or an applicable branch-specific patched version if the site is intentionally held on an older branch.
- Check whether automatic background updates completed, especially on sites with custom deployment processes or managed-hosting update controls.
- For complex or business-critical sites, use the existing staging, backup, or change-control process, but do not leave the security release pending longer than necessary.
- Review sites with public comments, pending moderation queues, contributor or author accounts, WXR export workflows, Imgur embeds, or custom code that interacts with post statuses and post types.
Related: Is WordPress right for your website? Tech Help Canada looks at costs, SEO, maintenance, flexibility, security considerations, and who the platform is best suited for.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







