{"id":16370708,"date":"2026-09-17T19:38:10","date_gmt":"2026-09-17T19:38:10","guid":{"rendered":"https:\/\/wordpress.org\/documentation\/?post_type=helphub_version&#038;p=16370708"},"modified":"2026-09-17T19:39:44","modified_gmt":"2026-09-17T19:39:44","slug":"version-7-1-1","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-1-1\/","title":{"rendered":"Version 7.1.1"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On September 17, 2026, WordPress 7.1.1 was released to the public.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit <a href=\"https:\/\/wordpress.org\/download\/releases\/\">https:\/\/wordpress.org\/download\/releases\/<\/a>.<br>For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/get-started-with-wordpress\/\">Get Started With WordPress<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/first-steps-with-wordpress-classic\/\">First Steps With WordPress<\/a> or <a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/upgrade\/upgrading\/\">Upgrading WordPress Extended<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/learn.wordpress.org\/courses\/\">WordPress Courses<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/adamsilverstein\/\">Adam Silverstein<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/adrianduffell\/\">Adrian Duffell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andraganescu\/\">Andrei Draganescu<\/a> and <a href=\"https:\/\/profiles.wordpress.org\/jorbin\/\">Aaron Jorbin<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This security and maintenance release includes <a href=\"https:\/\/core.trac.wordpress.org\/query?milestone=7.1.1&amp;status=closed&amp;group=status&amp;order=priority\">17 bug fixes on Core<\/a>, <a href=\"https:\/\/core.trac.wordpress.org\/changeset\/63587\">19 bug fixes for the Block Editor<\/a>, and 12 security fixes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a full list of bug fixes, please refer to the <a href=\"https:\/\/make.wordpress.org\/core\/2026\/09\/10\/wordpress-7-1-1-rc1-is-now-available\/\">release candidate announcement<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Security updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This security and maintenance release features <a href=\"https:\/\/core.trac.wordpress.org\/query?status=closed&amp;resolution=fixed&amp;milestone=7.1.1&amp;order=priority\">16 bug fixes on Core<\/a>, <a href=\"https:\/\/make.wordpress.org\/core\/2026\/09\/10\/wordpress-7-1-1-rc1-is-now-available\/\">21 bug fixes for the Block Editor<\/a>, and 12 security fixes. Because this is a security release, <strong>it is recommended that you update your sites immediately.<\/strong><br>The security team would like to thank the following people for <a href=\"https:\/\/hackerone.com\/wordpress?type=team\">responsibly reporting vulnerabilities<\/a>, and allowing them to be fixed in this release:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An issue allowing a crafted URL to install and preview a theme from WordPress.org reported by Paulos Yibelo and pwn.ai<\/li>\n\n\n\n<li>A stored cross-site scripting (XSS) issue in custom header images on some themes reported by Jeremy Felt of the WordPress Security Team<\/li>\n\n\n\n<li>An information disclosure issue exposing the title of a private parent post reported by HDWSec<\/li>\n\n\n\n<li>An HTML API issue allowing modified text to break out of an HTML comment reported by Jeremy Felt of the WordPress Security Team<\/li>\n\n\n\n<li>A multisite issue allowing a site administrator to network-activate a network-only plugin reported by Jesse McNeil<\/li>\n\n\n\n<li>A Contributor+ arbitrary post overwrite issue reported by Anthropic<\/li>\n\n\n\n<li>An authenticated path traversal issue in the REST API templates controller reported by Anthropic<\/li>\n\n\n\n<li>An authorization issue allowing any authenticated user to reparent comments, including notes, reported by viridis<\/li>\n\n\n\n<li>An XML-RPC issue allowing changeset posts to bypass the custom CSS capability check reported by Ben Bidner of the WordPress Security Team<\/li>\n\n\n\n<li>A Contributor+ disclosure of draft and pending post slugs reported by hermanhms<\/li>\n\n\n\n\n<li>An unauthenticated stored cross-site scripting (XSS) issue via paragraph formatting, subject to comment approval, reported by Rafie Muhammad (Awesome Motive, Inc.)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, <strong>only the most recent version of WordPress is actively supported.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>WordPress 7.0 is affected by all 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-5\/\">Version 7.0.5<\/a> has been released containing fixes for all of them.<\/li>\n\n\n\n<li>WordPress 6.9 is affected by all 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-8\/\">Version 6.9.8<\/a> has been released containing fixes for all of them.<\/li>\n\n\n\n<li>WordPress 6.8 is affected by all 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-8-9\/\">Version 6.8.9<\/a> has been released containing fixes for all of them.<\/li>\n\n\n\n<li>WordPress 6.7 is affected by all 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-7-8\/\">Version 6.7.8<\/a> has been released containing fixes for all of them.<\/li>\n\n\n\n<li>WordPress 6.6 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-6-8\/\">Version 6.6.8<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.5 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-5-11\/\">Version 6.5.11<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.4 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-4-11\/\">Version 6.4.11<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.3 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-3-11\/\">Version 6.3.11<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.2 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-2-12\/\">Version 6.2.12<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.1 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-1-13\/\">Version 6.1.13<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 6.0 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-0-15\/\">Version 6.0.15<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.9 is affected by 10 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-9-17\/\">Version 5.9.17<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.8 is affected by 9 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-8-16\/\">Version 5.8.16<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.7 is affected by 9 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-7-18\/\">Version 5.7.18<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.6 is affected by 9 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-6-20\/\">Version 5.6.20<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.5 is affected by 8 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-5-21\/\">Version 5.5.21<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.4 is affected by 8 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-4-22\/\">Version 5.4.22<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.3 is affected by 8 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-3-24\/\">Version 5.3.24<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.2 is affected by 7 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-2-27\/\">Version 5.2.27<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.1 is affected by 7 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-1-25\/\">Version 5.1.25<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 5.0 is affected by 7 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-0-28\/\">Version 5.0.28<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.9 is affected by 7 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-9-32\/\">Version 4.9.32<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.8 is affected by 7 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-8-31\/\">Version 4.8.31<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.7 is affected by 6 of the 11 vulnerabilities. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-7-36\/\">Version 4.7.36<\/a> has been released containing fixes.<\/li>\n\n\n\n<li>WordPress 4.6 and earlier no longer receive security updates.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Change log<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">List of files revised<\/h3>\n\n\n\n<pre class=\"wp-block-preformatted\">\/wp-admin\/includes\/ajax-actions.php<br>\/wp-admin\/includes\/class-custom-image-header.php<br>\/wp-admin\/includes\/media.php<br>\/wp-admin\/includes\/plugin.php<br>\/wp-admin\/includes\/post.php<br>\/wp-admin\/js\/theme.js<br>\/wp-includes\/block-template-utils.php<br>\/wp-includes\/class-wp-xmlrpc-server.php<br>\/wp-includes\/customize\/class-wp-customize-header-image-setting.php<br>\/wp-includes\/formatting.php<br>\/wp-includes\/html-api\/class-wp-html-tag-processor.php<br>\/wp-includes\/rest-api\/endpoints\/class-wp-rest-comments-controller.php<br>\/wp-includes\/theme.php<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">List of packages revised<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No package was revised.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>On September 17, 2026, WordPress 7.1.1 was released to the public. Installation\/Update Information To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit https:\/\/wordpress.org\/download\/releases\/.For step-by-step instructions on installing and updating WordPress: Updating WordPress If you are new to WordPress, we recommend that you begin with the [&hellip;]<\/p>\n","protected":false},"author":2097165,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":""},"helphub_major_release":[],"class_list":["post-16370708","helphub_version","type-helphub_version","status-publish","hentry"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16370708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/2097165"}],"version-history":[{"count":31,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16370708\/revisions"}],"predecessor-version":[{"id":16370854,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16370708\/revisions\/16370854"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=16370708"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=16370708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}