Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress 7.1.3, announced on October 6, 2026, includes seven security fixes and four bug fixes. WordPress recommends updating immediately. However, its 7.1.3 announcement does not identify any of those fixes as critical: the critical-severity wording appears in the release listing for WordPress 7.1.2, dated September 22, 2026.

What WordPress 7.1.3 fixes

WordPress.org groups the seven security fixes by issue type, but its announcement does not provide CVE identifiers, individual severity scores, affected-version ranges, or detailed exploit conditions. The descriptions below reflect the release-note summaries, not a complete technical advisory.

  • Stored cross-site scripting (XSS) in Comments administration: The issue involved pending comments. WordPress credits Thomas Chauchefoin of Trail of Bits.
  • Denial of service in WP_Http::make_absolute_url(): Reported by Anthropic.
  • Second-order SQL injection in WXR export: Reported by Anthropic.
  • Author-role permissions weakness: A weakness could allow users with the Author role to make posts sticky. Reported by Anthropic.
  • Disclosure of comments on private and unpublished posts: The release note describes this as unauthenticated disclosure. Reported by Ananda Dhakal of Patchstack.
  • XSS in Imgur embeds: Reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong.
  • Forgeable parameters passed to the {status}_{type} hook: The issue could lead to an action-name collision. Reported by Alex Concha of the WordPress security team.

WordPress.org also lists four bug fixes, but the security announcement does not detail them. It gives no CVSS score, affected-site count, or indication of whether any of these issues are being actively exploited.

Is the critical WordPress flaw fixed in 7.1.3?

The official materials support a distinction between the two releases: WordPress.org’s October 6 announcement describes 7.1.3 as containing seven security fixes, without calling any one of them critical. Its release listing associates the critical-severity security-fix language with WordPress 7.1.2, released September 22, 2026. The 7.1.3 announcement does not establish whether that earlier critical issue is included among the new fixes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

So the title’s critical-flaw wording should not be read as confirmation that 7.1.3 fixes one critical flaw. For the exact release notes and update recommendation, see the WordPress 7.1.3 announcement.

Should you update WordPress now?

Yes. WordPress.org says, “Because this is a security release, it is recommended that you update your sites immediately.” The recommendation applies to sites that can update to 7.1.3; older branches may receive security backports, but not every old installation is covered by an available fix.

The announcement says backports are being prepared where needed for branches eligible for security fixes, currently through 4.7, and will ship as ready. It also says only the most recent WordPress version is actively supported. That branch boundary and support status are those stated on October 6, 2026.

How to update to WordPress 7.1.3

  1. From the dashboard: Sign in to WordPress, open Dashboard → Updates, then choose Update Now.
  2. By download: Download WordPress 7.1.3 from WordPress.org and apply it using your site’s update process.
  3. Automatic update: Allow the automatic background update if it is supported and enabled for your installation.

WordPress.org lists these as the available update routes. The announcement does not provide a separate troubleshooting procedure for failed updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and what the release note does not establish

The official announcement provides a count and brief category-level descriptions, rather than issue-by-issue advisories. It does not establish the CVE IDs, affected-version ranges, exploit prerequisites, severity scores for each vulnerability, or current exploitation status. Those details should not be inferred from the short summaries.

Pantheon’s October 6 release note independently echoes the seven vulnerability categories. It also says Pantheon deployed a platform-wide routing-network mitigation for the stored XSS issue on its own platform. That is a Pantheon-specific measure, not evidence that other hosting providers have deployed the same mitigation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.