On October 6, 2026, WordPress 7.1.3 was released to the public.
Installation/Update Information
To get this version, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/releases/.
For step-by-step instructions on installing and updating WordPress:
If you are new to WordPress, we recommend that you begin with the following:
- Get Started With WordPress
- First Steps With WordPress or Upgrading WordPress Extended
- WordPress Courses
Summary
Security updates
This release features seven security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
- A DoS issue in the
WP_Http::make_absolute_url()method, reported by Anthropic - A second-Order SQL injection in WordPress WXR export, reported by Anthropic
- A weakness allowing Author role users to sticky posts, reported by Anthropic
- Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
- Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
- Forgeable parameters passed to the
{status}_{type}hook can lead to action name collision, reported by Alex Concha of the WordPress security team
As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
Change log
List of files revised
/wp-admin/js/common.js
/wp-admin/includes/export.php
/wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php
/wp-includes/class-wp-customize-manager.php
/wp-includes/class-wp-customize-setting.php
/wp-includes/class-wp-http.php
/wp-includes/class-wp-oembed.php
/wp-includes/class-wp-query.php
/wp-includes/post.php
List of packages revised
No package was revised.