WordPress officially launched version 7.1.3 on October 6. This crucial update successfully patches seven security vulnerabilities within the core platform. Furthermore, it resolves four annoying software bugs.
Vulnerability Discovery and Reporting
Artificial intelligence company Anthropic notably reported three of these seven security flaws. Meanwhile, Trail of Bits and Patchstack each identified one distinct vulnerability. Three independent researchers collaboratively submitted another concerning issue. Finally, the internal WordPress security team proactively discovered the last remaining flaw.
Dangerous Cross-Site Scripting Flaw
According to the official announcement, the most easily exploitable vulnerability resides in the comment management interface. Specifically, Thomas Chauchefoin from Trail of Bits reported this dangerous stored cross-site scripting (XSS) issue. Malicious scripts secretly lurk within the pending comment queue. Consequently, these dangerous scripts execute immediately when an unsuspecting administrator opens the moderation page.
WXR Exporter and Privilege Escalation Bugs
One of the three vulnerabilities reported by Anthropic specifically targets the WXR exporter tool. First, the system temporarily stores the attacker’s malicious input. However, this hidden payload only becomes a genuine threat during a content export. At that moment, the system unwittingly reuses the dangerous input to construct a database query.
Additionally, developers patched a severe denial-of-service vulnerability within the WP_Http::make_absolute_url() method. Furthermore, they resolved a frustrating privilege escalation flaw. Previously, this specific bug allowed standard author accounts to inappropriately mark posts as sticky without authorization.











