Threat reportVulnerabilityTL-2026-3259
WordPress 7.1.3 Security Release: Seven Fixes Including Stored XSS, Second-Order SQL Injection and Unauthenticated Comment Disclosure
WordPress 7.1.3 Security Release (TL-2026-3259), also tracked as WordPress 7.1.3 Security Release, is a medium-severity software vulnerability, first published 2026-10-10. It has no confirmed attribution, affects WordPress WordPress Core, maps to 6 MITRE ATT&CK techniques (T1059.007, T1078, T1190), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3259
- Threat ID
- TL-2026-3259
- Also known as
- WordPress 7.1.3 Security Release
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, news - media, ecommerce, government administration, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in WordPress 7.1.3 Security Release
Malware and tooling: PHP
How WordPress 7.1.3 Security Release works
WordPress 7.1.3 (released 2026-10-06) fixes seven security issues: stored XSS on the Comments admin page, XSS in Imgur embeds, second-order SQL injection in WXR export, unauthenticated disclosure of comments on private/unpublished posts, an Author-role sticky-post authorization weakness, forgeable {status}_{type} hook parameters, and a DoS in WP_Http::make_absolute_url(). No CVE IDs, CVSS scores, exploitation reports or public PoCs are stated in the sources.
WordPress 7.1.3 is a maintenance and security release published on 2026-10-06 (release leader Jake Spurlock) containing seven security fixes and four bug fixes. The vendor recommends updating immediately. The release is the third WordPress security update in 19 days, following 7.1.1 (2026-09-17) and 7.1.2 (2026-09-22). Fixes are backported to branches eligible for security fixes (currently through 4.7), although Patchstack noted that at publication time backports were available through 6.6 with 4.7-6.5 pending. Only the most recent WordPress version is actively supported.
Stored XSS on the Comments administration page (reported by Trail of Bits in collaboration with OpenAI; Cyber Security News credits Thomas Chauchefoin): per Patchstack the attack vector is a malicious link in a pending comment, requiring a moderator to click it, and affects 7.1.0-7.1.2. The root cause is jQuery's $() function processing link href attributes from pending comments as HTML, tied to class attributes added in 7.1.0. Imgur embeds were vulnerable to XSS (reported by Zhengyu Liu, Jingcheng Yang and Gavin Zhong): Patchstack states Imgur was incorrectly whitelisted as a trusted oEmbed provider, bypassing sandbox filtering of user-supplied content; cached oEmbed content persists after the update and may need to be cleared manually.
Second-order SQL injection in WXR export (reported by Anthropic): per Patchstack, unsanitized _thumbnail_id post metadata is used when an administrator exports a single content type (not the default 'All content' export); present since 6.5.0. Unauthenticated disclosure of comments on private and unpublished posts (reported by Ananda Dhakal, Patchstack): per Patchstack, comment visibility checks occurred after query execution, allowing unauthenticated access via a single-post feed. A weakness allowing Author-role users to make posts sticky (reported by Anthropic) is a REST API capability bypass. Forgeable parameters passed to the {status}_{type} hook can lead to action name collision (reported by Alex Concha of the WordPress security team); Patchstack says exploitation requires a dependent plugin plus post data manipulation. A DoS in WP_Http::make_absolute_url() (reported by Anthropic) is an infinite loop triggered via a regex pattern and requires Contributor+ access per Patchstack.
Revised files: /wp-admin/js/common.js, /wp-admin/includes/export.php, class-wp-rest-posts-controller.php, class-wp-customize-manager.php, class-wp-customize-setting.php, class-wp-http.php, class-wp-oembed.php, class-wp-query.php and post.php. No packages were revised. No CVE identifiers, CVSS scores, exploitation in the wild, public PoCs or CISA KEV listing are stated in any source; the Cyber Security News headline calling these 'critical' is not an official severity classification. Severity is set to MEDIUM by analyst judgment. No network IOCs were published, so no BeaconBeagle correlation applies.
MITRE ATT&CK techniques used in TL-2026-3259
Execution
T1059.007 JavaScript; T1204.001 Malicious Link
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Impact
Affected products and versions in WordPress 7.1.3 Security Release
- WordPress — WordPress Core
Vulnerable versions: 7.1.0-7.1.2 (Comments admin stored XSS); 6.5.0 and later (WXR export SQL injection); older branches eligible for security fixes, through 4.7
Fixed in: 7.1.3
Remediation for WordPress 7.1.3 Security Release
Patches
- WordPress 7.1.3
- Backports to older branches eligible for security fixes (through 4.7 per the announcement; Patchstack reported availability through 6.6 at publication)
Immediate actions
- Update to WordPress 7.1.3 via Dashboard > Updates or wordpress.org/download/releases
- Clear cached oEmbed content after updating so pre-existing malicious Imgur embeds are not rendered
- Review pending comments before moderating and avoid clicking links inside them until patched
Workarounds
- Until patched, avoid single-content-type WXR exports
- Restrict Contributor+ accounts and review feed exposure for private/unpublished posts
Longer-term hardening
- Enable automatic background security updates for WordPress core
- Audit Contributor and Author role assignments and apply least privilege
- Move off unsupported WordPress branches; only the latest version is actively supported
Timeline of WordPress 7.1.3 Security Release
- WordPress 7.1.1 released, the first of three security updates in 19 days (per drweb.de)
- WordPress 7.1.2 released as an emergency patch (per drweb.de)
- Anthropic AI-driven security research had disclosed 6,157 flaws across 591 projects as of this date (per drweb.de)
- Patchstack published technical analysis; backports available through 6.6, with 4.7-6.5 pending at publication
- WordPress 7.1.3 released with seven security fixes and four bug fixes; immediate update recommended
- Cyber Security News published coverage of the seven fixes
- Official 7.1.3 release notes page last modified
Sources cited for WordPress 7.1.3 Security Release
- WordPress Version 7.1.3 release notes
- WordPress 7.1.3 Maintenance and Security Release
- Patchstack: WordPress 7.1.3 Security Release
- Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks
- drweb.de: WordPress 7.1.3 - das dritte Sicherheitsupdate in 19 Tagen
- Pantheon release notes: WordPress 7.1.3
- WordPress HackerOne responsible disclosure program
Detection coverage for TL-2026-3259
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3259 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.