On September 17, 2026, WordPress 7.1.1 was released to the public.
Installation/Update Information
To get this version, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/releases/.
For step-by-step instructions on installing and updating WordPress:
If you are new to WordPress, we recommend that you begin with the following:
- Get Started With WordPress
- First Steps With WordPress or Upgrading WordPress Extended
- WordPress Courses
Summary
This release was led by Adam Silverstein, Adrian Duffell, Andrei Draganescu and Aaron Jorbin.
This security and maintenance release includes 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 12 security fixes.
For a full list of bug fixes, please refer to the release candidate announcement.
Security updates
This security and maintenance release features 16 bug fixes on Core, 21 bug fixes for the Block Editor, and 12 security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- An issue allowing a crafted URL to install and preview a theme from WordPress.org reported by Paulos Yibelo and pwn.ai
- A stored cross-site scripting (XSS) issue in custom header images on some themes reported by Jeremy Felt of the WordPress Security Team
- An information disclosure issue exposing the title of a private parent post reported by HDWSec
- An HTML API issue allowing modified text to break out of an HTML comment reported by Jeremy Felt of the WordPress Security Team
- A multisite issue allowing a site administrator to network-activate a network-only plugin reported by Jesse McNeil
- A Contributor+ arbitrary post overwrite issue reported by Anthropic
- An authenticated path traversal issue in the REST API templates controller reported by Anthropic
- An authorization issue allowing any authenticated user to reparent comments, including notes, reported by viridis
- An XML-RPC issue allowing changeset posts to bypass the custom CSS capability check reported by Ben Bidner of the WordPress Security Team
- A Contributor+ disclosure of draft and pending post slugs reported by hermanhms
- An unauthenticated stored cross-site scripting (XSS) issue via paragraph formatting, subject to comment approval, reported by Rafie Muhammad (Awesome Motive, Inc.)
As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
- WordPress 7.0 is affected by all 11 vulnerabilities. Version 7.0.5 has been released containing fixes for all of them.
- WordPress 6.9 is affected by all 11 vulnerabilities. Version 6.9.8 has been released containing fixes for all of them.
- WordPress 6.8 is affected by all 11 vulnerabilities. Version 6.8.9 has been released containing fixes for all of them.
- WordPress 6.7 is affected by all 11 vulnerabilities. Version 6.7.8 has been released containing fixes for all of them.
- WordPress 6.6 is affected by 10 of the 11 vulnerabilities. Version 6.6.8 has been released containing fixes.
- WordPress 6.5 is affected by 10 of the 11 vulnerabilities. Version 6.5.11 has been released containing fixes.
- WordPress 6.4 is affected by 10 of the 11 vulnerabilities. Version 6.4.11 has been released containing fixes.
- WordPress 6.3 is affected by 10 of the 11 vulnerabilities. Version 6.3.11 has been released containing fixes.
- WordPress 6.2 is affected by 10 of the 11 vulnerabilities. Version 6.2.12 has been released containing fixes.
- WordPress 6.1 is affected by 10 of the 11 vulnerabilities. Version 6.1.13 has been released containing fixes.
- WordPress 6.0 is affected by 10 of the 11 vulnerabilities. Version 6.0.15 has been released containing fixes.
- WordPress 5.9 is affected by 10 of the 11 vulnerabilities. Version 5.9.17 has been released containing fixes.
- WordPress 5.8 is affected by 9 of the 11 vulnerabilities. Version 5.8.16 has been released containing fixes.
- WordPress 5.7 is affected by 9 of the 11 vulnerabilities. Version 5.7.18 has been released containing fixes.
- WordPress 5.6 is affected by 9 of the 11 vulnerabilities. Version 5.6.20 has been released containing fixes.
- WordPress 5.5 is affected by 8 of the 11 vulnerabilities. Version 5.5.21 has been released containing fixes.
- WordPress 5.4 is affected by 8 of the 11 vulnerabilities. Version 5.4.22 has been released containing fixes.
- WordPress 5.3 is affected by 8 of the 11 vulnerabilities. Version 5.3.24 has been released containing fixes.
- WordPress 5.2 is affected by 7 of the 11 vulnerabilities. Version 5.2.27 has been released containing fixes.
- WordPress 5.1 is affected by 7 of the 11 vulnerabilities. Version 5.1.25 has been released containing fixes.
- WordPress 5.0 is affected by 7 of the 11 vulnerabilities. Version 5.0.28 has been released containing fixes.
- WordPress 4.9 is affected by 7 of the 11 vulnerabilities. Version 4.9.32 has been released containing fixes.
- WordPress 4.8 is affected by 7 of the 11 vulnerabilities. Version 4.8.31 has been released containing fixes.
- WordPress 4.7 is affected by 6 of the 11 vulnerabilities. Version 4.7.36 has been released containing fixes.
- WordPress 4.6 and earlier no longer receive security updates.
Change log
List of files revised
/wp-admin/includes/ajax-actions.php
/wp-admin/includes/class-custom-image-header.php
/wp-admin/includes/media.php
/wp-admin/includes/plugin.php
/wp-admin/includes/post.php
/wp-admin/js/theme.js
/wp-includes/block-template-utils.php
/wp-includes/class-wp-xmlrpc-server.php
/wp-includes/customize/class-wp-customize-header-image-setting.php
/wp-includes/formatting.php
/wp-includes/html-api/class-wp-html-tag-processor.php
/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
/wp-includes/theme.php
List of packages revised
No package was revised.