Critical WordPress Flaws Allow XSS, SQL Injection, Data Disclosure
Key Takeaways WordPress has released version 7.1.3, a critical security update addressing multiple vulnerabilities. The update fixes issues including cross-site scripting (XSS), SQL injection, and...
Key Takeaways
- WordPress has released version 7.1.3, a critical security update addressing multiple vulnerabilities.
- The update fixes issues including cross-site scripting (XSS), SQL injection, and sensitive information disclosure.
- Affected components range from comment administration and Imgur embeds to WXR export and HTTP processing.
- While specific CVEs and CVSS scores are not provided, WordPress urges immediate updates for all installations.
- Administrators should update their sites to version 7.1.3 to mitigate potential risks.
WordPress Addresses Critical Flaws in Latest Security Release
WordPress rolled out version 7.1.3 on October 6, 2026, a significant security release designed to patch several vulnerabilities, including cross-site scripting (XSS), SQL injection, and information disclosure weaknesses. The project has strongly advised all users to update their installations without delay, emphasizing that only the most current WordPress version receives active support.
Table Of Content
The official release documentation for 7.1.3 details seven distinct security issues, despite an initial statement mentioning “one security fix.” Notably, the announcement refrains from disclosing specific CVE identifiers, severity ratings, or any evidence of active exploitation. Therefore, while this article highlights the critical nature of these flaws, it’s important to note that this assessment is not an official severity classification for each individual vulnerability from WordPress itself.
Cross-Site Scripting Vulnerabilities Patched
Among the addressed issues is a stored cross-site scripting flaw discovered within the Comments administration page. This vulnerability creates an attack vector through pending comments, potentially compromising administrators when they review user-submitted content. Thomas Chauchefoin of Trail of Bits is credited with reporting this particular issue. The disclosure, however, does not elaborate on the specific malicious payload or the precise conditions required for successful exploitation.
A second XSS vulnerability has been identified affecting Imgur embeds. This separate weakness was reported by a team comprising Zhengyu Liu, Jingcheng Yang, and Gavin Zhong. These two XSS findings impact distinct content handling mechanisms—comment moderation and embedded external media—underscoring the broad relevance of this update for sites that process user-generated content or integrate third-party materials.
SQL Injection and Information Disclosure Risks
Anthropic reported a second-order SQL injection vulnerability impacting the WordPress WXR export function. While the export component is identified, the release notes do not detail the exact injection sequence, necessary user permissions, or the potential database impact. Consequently, administrators should exercise caution and avoid assuming this issue grants unrestricted database access or that all export operations are inherently exploitable.
Another significant vulnerability allows for the unauthorized disclosure of comments linked to private and unpublished posts. Reported by Ananda Dhakal of Patchstack, this flaw exposes information intended to remain inaccessible to the public. The announcement confirms that comments are the exposed data, but it does not suggest that attackers can retrieve the complete content of private posts.
Additional Security Weaknesses and Fixes
Anthropic also reported an authorization flaw enabling users with the “Author” role to inappropriately make posts “sticky.” This represents a privilege escalation issue related to publishing capabilities.
Separately, Alex Concha from the WordPress security team identified forgeable parameters passed to the {status}_{type} hook, which could lead to action name collisions. The broader implications and exploitation consequences of this particular issue remain unspecified in the release notes.
Finally, a denial-of-service (DoS) vulnerability was discovered affecting the WP_Http::make_absolute_url() method. This finding was also reported by Anthropic. However, WordPress’s release notes do not provide details regarding the specific request patterns that trigger the DoS, measurements of resource consumption, or detailed attack prerequisites.
WordPress 7.1.3 can be installed directly through the Dashboard > Updates section or downloaded from the official releases page. WordPress explicitly recommends immediate updates due to the security nature of this release. While fixes are also available for older affected branches, this does not alter the project’s policy of actively supporting only the latest version.
The updated files span various core components, including administration JavaScript, export handling, REST posts, customization, HTTP processing, embeds, queries, and post operations. No full package revisions were necessary.
What You Should Do
- Update Immediately: Upgrade all WordPress installations to version 7.1.3 without delay. This is a critical security release.
- Backup Your Site: Before initiating any updates, ensure you have a complete and recent backup of your WordPress site and database.
- Monitor for Anomalies: After updating, monitor your site for any unusual activity or performance issues.
- Review User Roles: Periodically audit user roles and permissions, especially if you have multiple contributors or authors, to ensure they align with your security policies.
- Stay Informed: Regularly check the official WordPress news and security announcements for further updates and advisories.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.