WordPress 7.1.3 has been released as a security and maintenance update, addressing seven security vulnerabilities along with four other bugs affecting the content management system.
Because the release includes multiple security fixes, WordPress recommends that users update their websites as soon as possible. Websites configured to receive automatic background updates may install the new version automatically, while other users can update through the WordPress Dashboard by going to Updates and selecting Update Now.
One of the security issues fixed in WordPress 7.1.3 is a stored cross-site scripting vulnerability affecting the Comments administration page. The issue could be exploited through pending comments and was reported by Thomas Chauchefoin of Trail of Bits.
The update also fixes a denial-of-service vulnerability in the WP_Http::make_absolute_url() method. The issue was reported by researchers at Anthropic.
Another security fix addresses a second-order SQL injection vulnerability in WordPress WXR export functionality, also reported by Anthropic. WordPress has additionally fixed a permissions-related weakness that could allow users with the Author role to make posts sticky.
The release also addresses an unauthenticated information disclosure issue that could expose comments associated with private or unpublished posts. The vulnerability was reported by Ananda Dhakal of Patchstack.
WordPress 7.1.3 also fixes a cross-site scripting vulnerability involving Imgur embeds. The issue was reported by security researchers Zhengyu Liu, Jingcheng Yang and Gavin Zhong.
The final security fix addresses forgeable parameters passed to the {status}_{type} hook, which could result in action name collisions. The issue was reported by Alex Concha from the WordPress security team.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
WordPress users can install version 7.1.3 directly from the Dashboard or download the latest release from WordPress.org. Since the update contains security fixes, site owners are strongly advised not to delay the update, particularly on websites that allow multiple users or accept comments and other user-generated content.



