WordPress 7.1.3 fixes seven flaws, including SQL injection in export
EditorialBy TrustList Editorial
The release also carries four bug fixes. Security backports to older branches, reaching back to 4.7, are still in progress and will ship as each becomes ready.
- WordPress
- Content Management
- Cybersecurity
- Vulnerability Management
About WordPress 7.1.3 fixes seven flaws, including SQL injection in export
WordPress 7.1.3 fixes seven flaws, including SQL injection in export
6 October 2026: WordPress 7.1.3 is a security and maintenance release that fixes seven vulnerabilities, among them a second-order SQL injection in the WXR export tool and a leak of comments on private and unpublished posts to unauthenticated visitors. The project says it also fixes four bugs and recommends updating immediately.
Not yet independently verified. Single source: the WordPress.org release post, which gives no CVE numbers or severity scores. We will add them when published. We will update this when it can be confirmed, and remove this note.
The release post lists the seven security fixes without CVE identifiers or severity ratings:
- a stored cross-site scripting (XSS) flaw on the Comments administration page, reachable through pending comments
- a denial-of-service problem in the WP_Http::make_absolute_url() method
- a second-order SQL injection in the WXR export
- a weakness that lets users with the Author role make posts sticky
- unauthenticated disclosure of comments on private and unpublished posts
- cross-site scripting in Imgur embeds
- forgeable parameters passed to the {status}_{type} hook, which can cause action-name collisions
The report credits Trail of Bits, Patchstack, the WordPress security team and several independent researchers.
Sites that allow automatic background updates will receive 7.1.3 on their own. Everyone else can use Dashboard, Updates, Update Now, or download the package from WordPress.org. The project reminds users that only the newest WordPress version is actively supported. It adds that the security fixes are being backported to every branch still eligible for them, currently back to 4.7, and that those backports will ship as they become ready. Owners of sites pinned to an older branch should therefore watch for their branch's own release rather than assume 7.1.3 applies.
The comment disclosure is the flaw most likely to matter to publishers and membership sites, because private-post comments often hold material meant for a restricted audience. Agencies running many sites should confirm which of them have background updates switched off.
Company profile on TrustList: WordPress
Sources
- WordPress.org: WordPress 7.1.3 Maintenance and Security Release, 6 October 2026
Categories & features
- WordPress
- Content Management
- Cybersecurity
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More WordPressThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.