{"id":101,"date":"2026-10-06T18:00:00","date_gmt":"2026-10-06T17:00:00","guid":{"rendered":"https:\/\/sripuwath.com\/index.php\/2026\/10\/06\/wordpress-org-blog-wordpress-7-1-3-maintenance-and-security-release\/"},"modified":"2026-10-06T18:00:00","modified_gmt":"2026-10-06T17:00:00","slug":"wordpress-org-blog-wordpress-7-1-3-maintenance-and-security-release","status":"publish","type":"post","link":"https:\/\/sripuwath.com\/index.php\/2026\/10\/06\/wordpress-org-blog-wordpress-7-1-3-maintenance-and-security-release\/","title":{"rendered":"WordPress.org blog: WordPress 7.1.3 Maintenance and Security Release"},"content":{"rendered":"<p class=\"wp-block-paragraph\">This security and maintenance release features 7 security fixes and <a href=\"https:\/\/core.trac.wordpress.org\/query?milestone=7.1.3&amp;status=closed&amp;order=priority&amp;col=id&amp;col=summary&amp;col=status&amp;col=milestone&amp;col=owner&amp;col=type&amp;col=priority\">4 bug fixes<\/a>.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Because this is a security release, it is recommended that you update your sites immediately.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">You can <a href=\"https:\/\/wordpress.org\/wordpress-7.1.3.zip\">download WordPress 7.1.3 from WordPress.org<\/a>, or visit your WordPress Dashboard, click \u201cUpdates\u201d, and then click \u201cUpdate Now\u201d. If you have sites that support automatic background updates, the update process will begin automatically.<\/p>\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people and organizations for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:<\/p>\n<ul class=\"wp-block-list\">\n<li>A stored XSS on the Comments administration page, exploitable via pending comments, reported by <a href=\"https:\/\/trailofbits.com\/\">Thomas Chauchefoin at Trail of Bits<\/a><\/li>\n<li>A DoS issue in the <code>WP_Http::make_absolute_url()<\/code> method, reported by Anthropic<\/li>\n<li>A second-Order SQL injection in WordPress WXR export, reported by Anthropic<\/li>\n<li>A weakness allowing Author role users to sticky posts, reported by Anthropic<\/li>\n<li>Unauthenticated disclosure of comments on private &amp; unpublished posts, reported by <a href=\"https:\/\/patchstack.com\/\">Ananda Dhakal from Patchstack<\/a><\/li>\n<li>Imgur embeds are vulnerable to XSS, reported by <a href=\"https:\/\/jackfromeast.github.io\/\">Zhengyu Liu<\/a>, <a href=\"https:\/\/jesse-yang.com\/\">Jingcheng Yang<\/a>, and <a href=\"https:\/\/gvzhong.github.io\/\">Gavin Zhong<\/a><\/li>\n<li>Forgeable parameters passed to the <code>{status}_{type}<\/code> hook can lead to action name collision, reported by Alex Concha of the WordPress security team<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/whyisjake\/\">Jake Spurlock<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">WordPress 7.1.3 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver maintenance and security fixes into a stable release is a testament to the power and capability of the WordPress community.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/w.org\/@jorbin\">Aaron Jorbin<\/a>,\u00a0<a href=\"https:\/\/w.org\/@adamsilverstein\">Adam Silverstein<\/a>,\u00a0<a href=\"https:\/\/w.org\/@adrianmoldovanwp\">Adi Moldovan<\/a>,\u00a0<a href=\"https:\/\/w.org\/@adrianduffell\">Adrian Duffell<\/a>,\u00a0<a href=\"https:\/\/w.org\/@xknown\">Alex Concha<\/a>,\u00a0<a href=\"https:\/\/w.org\/@arkaprabhachowdhury\">Arkaprabha Chowdhury<\/a>,\u00a0<a href=\"https:\/\/w.org\/@iamchitti\">Deepak Kumar<\/a>,\u00a0<a href=\"https:\/\/w.org\/@donniam\">donniam<\/a>,\u00a0<a href=\"https:\/\/w.org\/@ehtis\">Ehtisham Siddiqui<\/a>,\u00a0<a href=\"https:\/\/w.org\/@whyisjake\">Jake Spurlock<\/a>,\u00a0<a href=\"https:\/\/w.org\/@audrasjb\">Jb Audras<\/a>,\u00a0<a href=\"https:\/\/w.org\/@jeremyfelt\">Jeremy Felt<\/a>,\u00a0<a href=\"https:\/\/w.org\/@joedolson\">Joe Dolson<\/a>,\u00a0<a href=\"https:\/\/w.org\/@johnbillion\">John Blackbourn<\/a>,\u00a0<a href=\"https:\/\/w.org\/@jonsurrell\">Jon Surrell<\/a>,\u00a0<a href=\"https:\/\/w.org\/@desrosj\">Jonathan Desrosiers<\/a>,\u00a0<a href=\"https:\/\/w.org\/@kgagne\">Ken Gagne<\/a>,\u00a0<a href=\"https:\/\/w.org\/@khokansardar\">Khokan Sardar<\/a>,\u00a0<a href=\"https:\/\/w.org\/@lancewillett\">Lance Willett<\/a>,\u00a0<a href=\"https:\/\/w.org\/@lucatume\">lucatume<\/a>,\u00a0<a href=\"https:\/\/w.org\/@marcs0h\">marcs0h<\/a>,\u00a0<a href=\"https:\/\/w.org\/@peterwilsoncc\">Peter Wilson<\/a>,\u00a0<a href=\"https:\/\/w.org\/@pkevan\">pkevan<\/a>,\u00a0<a href=\"https:\/\/w.org\/@therssoftware\">RS Software<\/a>,\u00a0<a href=\"https:\/\/w.org\/@rfaile313\">Rudy Faile<\/a>,\u00a0<a href=\"https:\/\/w.org\/@sergeybiryukov\">Sergey Biryukov<\/a>,\u00a0<a href=\"https:\/\/w.org\/@siliconforks\">siliconforks<\/a>,\u00a0<a href=\"https:\/\/w.org\/@smerriman\">smerriman<\/a>,\u00a0<a href=\"https:\/\/w.org\/@sabernhardt\">Stephen Bernhardt<\/a>,\u00a0<a href=\"https:\/\/w.org\/@suryakantupadhyay\">Suryakant Upadhyay<\/a>,\u00a0<a href=\"https:\/\/w.org\/@vortfu\">vortfu<\/a>,\u00a0<a href=\"https:\/\/w.org\/@webverts\">webVerts<\/a>,\u00a0<a href=\"https:\/\/w.org\/@westonruter\">Weston Ruter<\/a>,\u00a0<a href=\"https:\/\/w.org\/@yogeshbhutkar\">Yogesh Bhutkar<\/a><\/p>\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n<p class=\"wp-block-paragraph\">As a courtesy, the security fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n<h2 class=\"wp-block-heading\">How to contribute<\/h2>\n<p class=\"wp-block-paragraph\">To get involved in WordPress core development, head over to Trac, <a href=\"https:\/\/core.trac.wordpress.org\/report\/6\">pick a ticket<\/a>, and join the conversation in the <a href=\"https:\/\/wordpress.slack.com\/archives\/C02RQBWTW\">#core<\/a> channel. Need help? Check out the <a href=\"https:\/\/make.wordpress.org\/core\/handbook\/\">Core Contributor Handbook<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>This security and maintenance release features 7 security fixes and 4 bug fixes. Because this is a security release, it is recommended that you update your sites immediately. You can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-101","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts\/101","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/comments?post=101"}],"version-history":[{"count":0,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts\/101\/revisions"}],"wp:attachment":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/media?parent=101"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/categories?post=101"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/tags?post=101"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}