Version 6.1.11

On August 6, 2026, WordPress 6.1.11 was released to the public.

Installation/Update Information

To get this version, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/releases/.
For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A bypass of the email address confirmation flow reported by 0ways
  • An Author+ CSS injection issue via a bypass of the safe CSS attribute filter reported by Anthropic
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
  • A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai
  • An enumeration of post slugs reported by HDWSec
  • A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal

Change log

List of files revised

/wp-admin/includes/user.php
/wp-admin/js/inline-edit-post.js
/wp-includes/blocks/post-date.php
/wp-includes/canonical.php
/wp-includes/http.php
/wp-includes/kses.php
/wp-includes/user.php
/wp-login.php
/wp-signup.php

List of packages revised

@wordpress/block-library - 7.14.16

First published

Last updated