WordPress 7.1.3 security release lists seven fixes without CVEs
WordPress 7.1.3 (6 October 2026) is a maintenance and security release with seven security fixes and four bug fixes. The official advisory names each issue and reporter but publishes no CVE ids and no CVSS scores. Update to 7.1.3. Not in CISA KEV as CVE-tracked entries for these fixes.
Published 7 Oct 2026
What happened
On 6 October 2026 WordPress published version 7.1.3 as a maintenance and security release. The official News post by Jake Spurlock states that the release features seven security fixes and four bug fixes, and recommends updating sites immediately. Unlike the prior 7.1.2 security release, which explicitly cited CVE-2026-87902 / GHSA-7hp8-65ch-5whp, the 7.1.3 advisory does not assign CVE identifiers or CVSS scores to the seven issues. ThreatWire therefore creates no CVE records for this batch and documents the vendor-listed fixes only.
Who is affected
Sites running WordPress below 7.1.3 are in scope for the issues named in the advisory until they update. The News post says security fixes are being backported, where necessary, to all branches eligible for security fixes (currently through 4.7), with backports in progress. Only the most recent WordPress version is actively supported. Exact preconditions differ by issue (unauthenticated visitors, pending comments plus a moderator, Author or Contributor roles, or an administrator export); the official post does not publish severity labels for those paths.
What is confirmed
From the WordPress.org News security section, the seven fixed issues and credited reporters are:
- Stored XSS on the Comments administration page, exploitable via pending comments — Thomas Chauchefoin (Trail of Bits).
- Denial-of-service in
WP_Http::make_absolute_url()— Anthropic. - Second-order SQL injection in WordPress WXR export — Anthropic.
- Weakness allowing Author-role users to sticky posts — Anthropic.
- Unauthenticated disclosure of comments on private and unpublished posts — Ananda Dhakal (Patchstack).
- Imgur embeds vulnerable to XSS — Zhengyu Liu, Jingcheng Yang, and Gavin Zhong.
- Forgeable parameters passed to the
{status}_{type}hook that can lead to action-name collision — Alex Concha (WordPress security team).
The version documentation page lists revised core files including export, HTTP, oEmbed, query, REST posts, Customize, and admin common.js paths consistent with those areas. NVD keyword and publication-window searches around this release did not turn up CVE records for these seven WordPress core fixes at drafting time. None of these issues appear as CVE entries in CISA KEV. No public PoC repository tied to a CVE id for this release was confirmed, and the advisory itself does not present exploit code.
What is not confirmed
CVE ids, CVSS vectors, and official severity ratings for the seven 7.1.3 fixes are not published in the WordPress News advisory. ThreatWire does not invent CVE numbers. Exploitation in the wild is not stated by WordPress for this release. Third-party write-ups that add auth matrices or implementation detail beyond the News list are useful context but are not CVE assignments. The four maintenance bug fixes are counted in the News headline; that post does not enumerate them in the security thank-you list.
What to do
Update to WordPress 7.1.3 from Dashboard → Updates, or from WordPress.org releases. Sites with automatic background updates should receive it automatically. After updating, review who holds Contributor, Author, and Editor roles, and clear caches if historical oEmbed content may retain older embed behavior. Watch WordPress.org for security backports on older branches if you still run them.
Sources: WordPress News “WordPress 7.1.3 Maintenance and Security Release,” the Version 7.1.3 documentation page, NVD search around the release window, and CISA KEV (no matching CVE listings for these unassigned fixes).