Daily Tech Now

Daily News on AI, Big Tech, Linux, Security & Gadgets

WordPress 7.1.3 Update Fixes Crucial Security Flaws

WordPress officially launched version 7.1.3 on October 6. This crucial update successfully patches seven security vulnerabilities within the core platform. Furthermore, it resolves four annoying software bugs. Vulnerability Discovery and Reporting Artificial intelligence company Anthropic notably reported three of these seven security flaws. Meanwhile, Trail of Bits and Patchstack each identified one distinct vulnerability. Three…

WordPress 7.1.3 update dashboard highlighting security vulnerabilities patch

WordPress officially launched version 7.1.3 on October 6. This crucial update successfully patches seven security vulnerabilities within the core platform. Furthermore, it resolves four annoying software bugs.

Vulnerability Discovery and Reporting

Artificial intelligence company Anthropic notably reported three of these seven security flaws. Meanwhile, Trail of Bits and Patchstack each identified one distinct vulnerability. Three independent researchers collaboratively submitted another concerning issue. Finally, the internal WordPress security team proactively discovered the last remaining flaw.

Dangerous Cross-Site Scripting Flaw

According to the official announcement, the most easily exploitable vulnerability resides in the comment management interface. Specifically, Thomas Chauchefoin from Trail of Bits reported this dangerous stored cross-site scripting (XSS) issue. Malicious scripts secretly lurk within the pending comment queue. Consequently, these dangerous scripts execute immediately when an unsuspecting administrator opens the moderation page.

WXR Exporter and Privilege Escalation Bugs

One of the three vulnerabilities reported by Anthropic specifically targets the WXR exporter tool. First, the system temporarily stores the attacker’s malicious input. However, this hidden payload only becomes a genuine threat during a content export. At that moment, the system unwittingly reuses the dangerous input to construct a database query.

Additionally, developers patched a severe denial-of-service vulnerability within the WP_Http::make_absolute_url() method. Furthermore, they resolved a frustrating privilege escalation flaw. Previously, this specific bug allowed standard author accounts to inappropriately mark posts as sticky without authorization.

About the Author

Trang Nguyen Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *