Title: Version 7.1.1
Author: Lance Willett
Published: September 17, 2026

---

# Version 7.1.1

## In this article

 * [Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#installation-update-information)
 * [Summary](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#summary)
    - [Security updates](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#security-updates)
 * [Change log](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#change-log)
    - [List of files revised](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#list-of-files-revised)
    - [List of packages revised](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#list-of-packages-revised)

[ Back to top](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#wp--skip-link--target)

On September 17, 2026, WordPress 7.1.1 was released to the public.

## 󠀁[Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#installation-update-information)󠁿

To get this version, update automatically from the Dashboard > Updates menu in your
site’s admin area or visit [https://wordpress.org/download/releases/](https://wordpress.org/download/releases/).

For step-by-step instructions on installing and updating WordPress:

 * [Updating WordPress](https://wordpress.org/documentation/article/updating-wordpress/)

If you are new to WordPress, we recommend that you begin with the following:

 * [Get Started With WordPress](https://wordpress.org/documentation/article/get-started-with-wordpress/)
 * [First Steps With WordPress](https://wordpress.org/documentation/article/first-steps-with-wordpress-classic/)
   or [Upgrading WordPress Extended](https://developer.wordpress.org/advanced-administration/upgrade/upgrading/)
 * [WordPress Courses](https://learn.wordpress.org/courses/)

## 󠀁[Summary](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#summary)󠁿

This release was led by [Adam Silverstein](https://profiles.wordpress.org/adamsilverstein/),
[Adrian Duffell](https://profiles.wordpress.org/adrianduffell/), [Andrei Draganescu](https://profiles.wordpress.org/andraganescu/)
and [Aaron Jorbin](https://profiles.wordpress.org/jorbin/).

This security and maintenance release includes [17 bug fixes on Core](https://core.trac.wordpress.org/query?milestone=7.1.1&status=closed&group=status&order=priority),
[21 bug fixes for the Block Editor](https://core.trac.wordpress.org/changeset/63587),
and 11 security fixes.

For a full list of bug fixes, please refer to the [release candidate announcement](https://make.wordpress.org/core/2026/09/10/wordpress-7-1-1-rc1-is-now-available/).

### 󠀁[Security updates](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#security-updates)󠁿

This security and maintenance release features [17 bug fixes on Core](https://core.trac.wordpress.org/query?milestone=7.1.1&status=closed&group=status&order=priority),
[21 bug fixes for the Block Editor](https://core.trac.wordpress.org/changeset/63587),
and 11 security fixes. Because this is a security release, **it is recommended that
you update your sites immediately.**
The security team would like to thank the following
people for [responsibly reporting vulnerabilities](https://hackerone.com/wordpress?type=team),
and allowing them to be fixed in this release:

 * An issue allowing a crafted URL to install and preview a theme from WordPress.
   org reported by Paulos Yibelo and pwn.ai
 * A stored cross-site scripting (XSS) issue in custom header images on some themes
   reported by Jeremy Felt of the WordPress Security Team
 * An information disclosure issue exposing the title of a private parent post reported
   by HDWSec
 * An HTML API issue allowing modified text to break out of an HTML comment reported
   by Jeremy Felt of the WordPress Security Team
 * A multisite issue allowing a site administrator to network-activate a network-
   only plugin reported by Jesse McNeil
 * A Contributor+ arbitrary post overwrite issue reported by Anthropic
 * An authenticated path traversal issue in the REST API templates controller reported
   by Anthropic
 * An authorization issue allowing any authenticated user to reparent comments, 
   including notes, reported by viridis
 * An XML-RPC issue allowing changeset posts to bypass the custom CSS capability
   check reported by Ben Bidner of the WordPress Security Team
 * A Contributor+ disclosure of draft and pending post slugs reported by hermanhms
 * An unauthenticated stored cross-site scripting (XSS) issue via paragraph formatting,
   subject to comment approval, reported by Rafie Muhammad (Awesome Motive, Inc.)

As a courtesy, these fixes are also available in older affected branches of WordPress.
As a reminder, **only the most recent version of WordPress is actively supported.**

 * WordPress 7.0 is affected by all 11 vulnerabilities. [Version 7.0.5](https://wordpress.org/documentation/wordpress-version/version-7-0-5/)
   has been released containing fixes for all of them.
 * WordPress 6.9 is affected by all 11 vulnerabilities. [Version 6.9.8](https://wordpress.org/documentation/wordpress-version/version-6-9-8/)
   has been released containing fixes for all of them.
 * WordPress 6.8 is affected by all 11 vulnerabilities. [Version 6.8.9](https://wordpress.org/documentation/wordpress-version/version-6-8-9/)
   has been released containing fixes for all of them.
 * WordPress 6.7 is affected by all 11 vulnerabilities. [Version 6.7.8](https://wordpress.org/documentation/wordpress-version/version-6-7-8/)
   has been released containing fixes for all of them.
 * WordPress 6.6 is affected by 10 of the 11 vulnerabilities. [Version 6.6.8](https://wordpress.org/documentation/wordpress-version/version-6-6-8/)
   has been released containing fixes.
 * WordPress 6.5 is affected by 10 of the 11 vulnerabilities. [Version 6.5.11](https://wordpress.org/documentation/wordpress-version/version-6-5-11/)
   has been released containing fixes.
 * WordPress 6.4 is affected by 10 of the 11 vulnerabilities. [Version 6.4.11](https://wordpress.org/documentation/wordpress-version/version-6-4-11/)
   has been released containing fixes.
 * WordPress 6.3 is affected by 10 of the 11 vulnerabilities. [Version 6.3.11](https://wordpress.org/documentation/wordpress-version/version-6-3-11/)
   has been released containing fixes.
 * WordPress 6.2 is affected by 10 of the 11 vulnerabilities. [Version 6.2.12](https://wordpress.org/documentation/wordpress-version/version-6-2-12/)
   has been released containing fixes.
 * WordPress 6.1 is affected by 10 of the 11 vulnerabilities. [Version 6.1.13](https://wordpress.org/documentation/wordpress-version/version-6-1-13/)
   has been released containing fixes.
 * WordPress 6.0 is affected by 10 of the 11 vulnerabilities. [Version 6.0.15](https://wordpress.org/documentation/wordpress-version/version-6-0-15/)
   has been released containing fixes.
 * WordPress 5.9 is affected by 10 of the 11 vulnerabilities. [Version 5.9.17](https://wordpress.org/documentation/wordpress-version/version-5-9-17/)
   has been released containing fixes.
 * WordPress 5.8 is affected by 9 of the 11 vulnerabilities. [Version 5.8.16](https://wordpress.org/documentation/wordpress-version/version-5-8-16/)
   has been released containing fixes.
 * WordPress 5.7 is affected by 9 of the 11 vulnerabilities. [Version 5.7.18](https://wordpress.org/documentation/wordpress-version/version-5-7-18/)
   has been released containing fixes.
 * WordPress 5.6 is affected by 9 of the 11 vulnerabilities. [Version 5.6.20](https://wordpress.org/documentation/wordpress-version/version-5-6-20/)
   has been released containing fixes.
 * WordPress 5.5 is affected by 8 of the 11 vulnerabilities. [Version 5.5.21](https://wordpress.org/documentation/wordpress-version/version-5-5-21/)
   has been released containing fixes.
 * WordPress 5.4 is affected by 8 of the 11 vulnerabilities. [Version 5.4.22](https://wordpress.org/documentation/wordpress-version/version-5-4-22/)
   has been released containing fixes.
 * WordPress 5.3 is affected by 8 of the 11 vulnerabilities. [Version 5.3.24](https://wordpress.org/documentation/wordpress-version/version-5-3-24/)
   has been released containing fixes.
 * WordPress 5.2 is affected by 7 of the 11 vulnerabilities. [Version 5.2.27](https://wordpress.org/documentation/wordpress-version/version-5-2-27/)
   has been released containing fixes.
 * WordPress 5.1 is affected by 7 of the 11 vulnerabilities. [Version 5.1.25](https://wordpress.org/documentation/wordpress-version/version-5-1-25/)
   has been released containing fixes.
 * WordPress 5.0 is affected by 7 of the 11 vulnerabilities. [Version 5.0.28](https://wordpress.org/documentation/wordpress-version/version-5-0-28/)
   has been released containing fixes.
 * WordPress 4.9 is affected by 7 of the 11 vulnerabilities. [Version 4.9.32](https://wordpress.org/documentation/wordpress-version/version-4-9-32/)
   has been released containing fixes.
 * WordPress 4.8 is affected by 7 of the 11 vulnerabilities. [Version 4.8.31](https://wordpress.org/documentation/wordpress-version/version-4-8-31/)
   has been released containing fixes.
 * WordPress 4.7 is affected by 6 of the 11 vulnerabilities. [Version 4.7.36](https://wordpress.org/documentation/wordpress-version/version-4-7-36/)
   has been released containing fixes.
 * WordPress 4.6 and earlier no longer receive security updates.

## 󠀁[Change log](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#change-log)󠁿

### 󠀁[List of files revised](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#list-of-files-revised)󠁿

    ```wp-block-preformatted
    /wp-admin/includes/ajax-actions.php/wp-admin/includes/class-custom-image-header.php/wp-admin/includes/media.php/wp-admin/includes/plugin.php/wp-admin/includes/post.php/wp-admin/js/theme.js/wp-includes/block-template-utils.php/wp-includes/class-wp-xmlrpc-server.php/wp-includes/customize/class-wp-customize-header-image-setting.php/wp-includes/formatting.php/wp-includes/html-api/class-wp-html-tag-processor.php/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php/wp-includes/theme.php
    ```

### 󠀁[List of packages revised](https://wordpress.org/documentation/wordpress-version/version-7.1.1/?output_format=md#list-of-packages-revised)󠁿

No package was revised.

First published

September 17, 2026

Last updated

September 17, 2026