# WordPress 7.1.3 Security Release: Seven Fixes Including Stored XSS, Second-Order SQL Injection and Unauthenticated Comment Disclosure

> WordPress 7.1.3 (released 2026-10-06) fixes seven security issues: stored XSS on the Comments admin page, XSS in Imgur embeds, second-order SQL injection in WXR export, unauthenticated disclosure of comments on private/unpublished posts, an Author-role sticky-post authorization weakness, forgeable {status}_{type} hook parameters, and a DoS in WP_Http::make_absolute_url(). No CVE IDs, CVSS scores, exploitation reports or public PoCs are stated in the sources.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3259
- **ID:** TL-2026-3259
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

WordPress 7.1.3 is a maintenance and security release published on 2026-10-06 (release leader Jake Spurlock) containing seven security fixes and four bug fixes. The vendor recommends updating immediately. The release is the third WordPress security update in 19 days, following 7.1.1 (2026-09-17) and 7.1.2 (2026-09-22). Fixes are backported to branches eligible for security fixes (currently through 4.7), although Patchstack noted that at publication time backports were available through 6.6 with 4.7-6.5 pending. Only the most recent WordPress version is actively supported.

Stored XSS on the Comments administration page (reported by Trail of Bits in collaboration with OpenAI; Cyber Security News credits Thomas Chauchefoin): per Patchstack the attack vector is a malicious link in a pending comment, requiring a moderator to click it, and affects 7.1.0-7.1.2. The root cause is jQuery's $() function processing link href attributes from pending comments as HTML, tied to class attributes added in 7.1.0. Imgur embeds were vulnerable to XSS (reported by Zhengyu Liu, Jingcheng Yang and Gavin Zhong): Patchstack states Imgur was incorrectly whitelisted as a trusted oEmbed provider, bypassing sandbox filtering of user-supplied content; cached oEmbed content persists after the update and may need to be cleared manually.

Second-order SQL injection in WXR export (reported by Anthropic): per Patchstack, unsanitized _thumbnail_id post metadata is used when an administrator exports a single content type (not the default 'All content' export); present since 6.5.0. Unauthenticated disclosure of comments on private and unpublished posts (reported by Ananda Dhakal, Patchstack): per Patchstack, comment visibility checks occurred after query execution, allowing unauthenticated access via a single-post feed. A weakness allowing Author-role users to make posts sticky (reported by Anthropic) is a REST API capability bypass. Forgeable parameters passed to the {status}_{type} hook can lead to action name collision (reported by Alex Concha of the WordPress security team); Patchstack says exploitation requires a dependent plugin plus post data manipulation. A DoS in WP_Http::make_absolute_url() (reported by Anthropic) is an infinite loop triggered via a regex pattern and requires Contributor+ access per Patchstack.

Revised files: /wp-admin/js/common.js, /wp-admin/includes/export.php, class-wp-rest-posts-controller.php, class-wp-customize-manager.php, class-wp-customize-setting.php, class-wp-http.php, class-wp-oembed.php, class-wp-query.php and post.php. No packages were revised. No CVE identifiers, CVSS scores, exploitation in the wild, public PoCs or CISA KEV listing are stated in any source; the Cyber Security News headline calling these 'critical' is not an official severity classification. Severity is set to MEDIUM by analyst judgment. No network IOCs were published, so no BeaconBeagle correlation applies.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059.007 JavaScript
- T1204.001 Malicious Link
- T1213 Data from Information Repositories
- T1499.004 Application or System Exploitation

## Sources

- [WordPress Version 7.1.3 release notes](https://wordpress.org/documentation/wordpress-version/version-7-1-3/)
- [WordPress 7.1.3 Maintenance and Security Release](https://wordpress.org/news/?p=21753)
- [Patchstack: WordPress 7.1.3 Security Release](https://patchstack.com/articles/wordpress-7-1-3-security-release/)
- [Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks](https://cybersecuritynews.com/wordpress-vulnerabilities/)
- [drweb.de: WordPress 7.1.3 - das dritte Sicherheitsupdate in 19 Tagen](https://www.drweb.de/wordpress-7-1-3-das-dritte-sicherheitsupdate-in-19-tagen/)
- [Pantheon release notes: WordPress 7.1.3](https://docs.pantheon.io/release-notes/2026/10/wordpress-7-1-3)
- [WordPress HackerOne responsible disclosure program](https://hackerone.com/wordpress?type=team)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3259
