WordPress has released version 7.1.3, described as a maintenance and security release that includes seven security fixes and four bug fixes. The release notes emphasize that, because this is a security release, sites should be updated promptly.
HOW TO UPDATE
You can download WordPress 7.1.3 from WordPress.org, or update from your WordPress Dashboard by navigating to Updates and selecting Update Now. TechStaged has also covered MiniMax H3 and H3 Max Hit 50% Off on AI Gateway Through Sept. 13.
If your sites support automatic background updates, the update will begin automatically where supported.
SECURITY FIXES ADDRESSED IN 7.1.3
The security fixes cover multiple vulnerabilities including a stored XSS on the Comments administration page (exploitable via pending comments), a DoS issue in WP_Http::make_absolute_url(), and a second-order SQL injection in WordPress WXR export. Other fixes include a weakness allowing Author role users to sticky posts, unauthenticated disclosure of comments on private and unpublished posts, issues with Imgur embeds potentially triggering XSS, and forgeable parameters passed to the {status}_{type} hook that could lead to action name collisions.
CONTEXT AND SUPPORT
This release is led by Jake Spurlock. The WordPress security team notes that backports are being applied where possible to older branches, and that only the most recent version is actively supported. The backports will ship as they become ready.
RELATED COVERAGE
SOURCES
- WordPress News: WordPress 7.1.3 Maintenance and Security Release Published · Primary source







