WordPress security update: 7.1.3 fixes seven security issues
WordPress 7.1.3 is a maintenance and security release that addresses seven security issues and four bug fixes. WordPress.org recommends updating sites immediately; here is what changed and what to do.
WordPress released a maintenance and security update, version 7.1.3, that includes seven security fixes and four bug fixes, and WordPress.org recommends that site owners update immediately. The release notes list the specific issues fixed, who reported them, and instructions for obtaining the update via the Dashboard or WordPress.org.
WordPress security update: what changed
According to WordPress.org, the 7.1.3 release closes seven security issues and adds four maintenance fixes. The security items cover a range of problems, including a stored cross-site scripting issue on the Comments administration page that could be triggered by pending comments, a denial of service problem in the WP_Http::make_absolute_url() method, and a second-order SQL injection in the WordPress WXR export.
Other fixes listed by WordPress.org address a weakness that allowed users with the Author role to make posts sticky, an unauthenticated disclosure of comments on private or unpublished posts, cross-site scripting in Imgur embeds, and a case where forgeable parameters passed to certain hooks could cause action name collisions. The release notes also credit the people and organizations that reported each issue and say the release was led by Jake Spurlock.
Why this matters for small sites and nonprofits
These are server-side core issues, not limited to a single plugin or theme, so they affect the WordPress core used by many sites. Problems like stored XSS and SQL injection can lead to data exposure or malicious content being stored in the site database, while DoS issues can cause service interruptions. The Author role weakness is an example of a configuration or permission problem that attackers could exploit without needing administrative access.
WordPress.org also says that, as a courtesy, the security fixes are being backported where necessary to branches eligible to receive security fixes, currently through 4.7. That means older supported branches may receive fixes as they become available, but only the most recent version is actively supported.
How to update right now
WordPress.org provides two primary update paths: download the release from WordPress.org, or use the Dashboard. If you prefer the Dashboard, go to Updates and click Update Now. Sites that support automatic background updates will begin the process on their own, according to WordPress.org.
Practical steps to follow now:
- Back up your site files and database before applying the update, especially on production sites.
- Apply the update through Dashboard > Updates, or download 7.1.3 from WordPress.org.
- If you have staging or a test environment, apply the update there first to check for compatibility issues with themes and plugins.
- After updating, review comment moderation and pending comments for any unexpected content or changes, since a stored XSS issue on the Comments screen was fixed.
- Review user roles and capabilities, paying attention to Author accounts and what actions they can take now that an Author role weakness was fixed.
What to check after you update
- Look through recent comment activity and review pending comments for anything suspicious, since the release addresses comment-related XSS and disclosure issues.
- If you export or import site content, note that the WXR export had a second-order SQL injection that was fixed; test any export/import workflows you use.
- Audit your plugins and themes for custom use of hooks or filters, because one fix concerns forgeable parameters passed to hook names.
If you need help or want a second opinion
If you run WordPress or Formidable Forms and want a developer to review updates, compatibility, or permission settings, we can help. Contact us at our site for support and audits: /contact.html
Final notes on support and backports
WordPress.org says the security fixes are being backported to supported branches where necessary, and that only the most recent version is actively supported. The release notes credit the researchers and organizations that reported the issues, and emphasize updating as the recommended action. For most sites the immediate priority is to apply the 7.1.3 update, test functionality, and review comments and Author-level permissions after the update.
For full details and the official download, see the release post on WordPress.org: https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release
Sources
- WordPress 7.1.3 Maintenance and Security Release WordPress.org
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.