Skip to content
TrustList
News

WordPress 7.1.3 fixes seven flaws, including SQL injection in export

Editorial

By TrustList Editorial

The release also carries four bug fixes. Security backports to older branches, reaching back to 4.7, are still in progress and will ship as each becomes ready.

About WordPress 7.1.3 fixes seven flaws, including SQL injection in export

WordPress 7.1.3 fixes seven flaws, including SQL injection in export

6 October 2026: WordPress 7.1.3 is a security and maintenance release that fixes seven vulnerabilities, among them a second-order SQL injection in the WXR export tool and a leak of comments on private and unpublished posts to unauthenticated visitors. The project says it also fixes four bugs and recommends updating immediately.

Not yet independently verified. Single source: the WordPress.org release post, which gives no CVE numbers or severity scores. We will add them when published. We will update this when it can be confirmed, and remove this note.

The release post lists the seven security fixes without CVE identifiers or severity ratings:

  • a stored cross-site scripting (XSS) flaw on the Comments administration page, reachable through pending comments
  • a denial-of-service problem in the WP_Http::make_absolute_url() method
  • a second-order SQL injection in the WXR export
  • a weakness that lets users with the Author role make posts sticky
  • unauthenticated disclosure of comments on private and unpublished posts
  • cross-site scripting in Imgur embeds
  • forgeable parameters passed to the {status}_{type} hook, which can cause action-name collisions

The report credits Trail of Bits, Patchstack, the WordPress security team and several independent researchers.

Sites that allow automatic background updates will receive 7.1.3 on their own. Everyone else can use Dashboard, Updates, Update Now, or download the package from WordPress.org. The project reminds users that only the newest WordPress version is actively supported. It adds that the security fixes are being backported to every branch still eligible for them, currently back to 4.7, and that those backports will ship as they become ready. Owners of sites pinned to an older branch should therefore watch for their branch's own release rather than assume 7.1.3 applies.

The comment disclosure is the flaw most likely to matter to publishers and membership sites, because private-post comments often hold material meant for a restricted audience. Agencies running many sites should confirm which of them have background updates switched off.

Company profile on TrustList: WordPress

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy