Save up to 20% on hosting, domains, Cloud VPS & Managed VPS for a successful business launch!

Get a free gift mug with selected hosting plans!

WordPress 7.1.3: Seven Security Fixes, Update Your Site

Георги Димитров Георги Димитров 8 min read
WordPress 7.1.3: Seven Security Fixes, Update Your Site
Summarize this article with: Summarize with:

On 6 October 2026, the WordPress team released WordPress 7.1.3. It is the next maintenance update after WordPress 7.1.1 and the urgent WordPress 7.1.2 from September. It brings 7 security fixes and 4 bug fixes.

There is no critical vulnerability this time, but the fixes touch things almost every site uses: comments, embedded content and user roles. The fix is already available and quick to apply. In this article we explain what happened and what you need to do next, without unnecessary technical detail.

In short

On 6 October 2026, WordPress 7.1.3 was released with fixes for 7 vulnerabilities and 4 bugs. Sites on 7.1.2 and older are affected, including those updated to 7.1.2 in September, and the scope differs for each vulnerability. WordPress has released fixes for every branch from 4.7 onwards. Two of the vulnerabilities can be used without an account on the site. We recommend updating your site to version 7.1.3 without delay. If you need help, the Jump.bg team is here for you.

What happened

The new version fixes 7 vulnerabilities in WordPress core. Most of them require the attacker to already have an account on the site, but two can be used by any visitor. The table below explains them in plain language:

Vulnerability What it could allow Who could use it
Hidden code in pending comments Running a malicious script in the admin area if a moderator clicks a link in a comment that is still waiting for approval. Any visitor, no account needed
Leaked comments Reading the comments on private and unpublished posts, which should stay hidden. Any visitor, no account needed
Hidden code in Imgur embeds Injecting a script into a page through an embedded Imgur image or album. A user with the Contributor role or higher
Overloading the site Tying up the server with a specially crafted link, for example when previewing a link in the editor. A user with the Contributor role or higher
Pinning posts without permission Pinning a post to the top of the blog (sticky), which is normally reserved for editors. A user with the Author role
Tampered database query Running an injected database query when an administrator exports content (Tools → Export). Requires data planted in the site beforehand and an action by an administrator
Confused internal signals Triggering plugin actions by mistake, for example as if a post had been deleted. Depends on the plugins in use

The comment vulnerability deserves a closer look, because it continues the story from WordPress 7.1.1. Back then, a malicious comment had no effect until it was approved. This time no approval is needed: it is enough for a moderator to click a link in a comment that is still waiting for review. The issue only affects versions 7.1 to 7.1.2, because it relies on a change to comments introduced in WordPress 7.1 (according to Patchstack's analysis). So until you update your site, do not click links in pending comments.

The second vulnerability that needs no account lets an outsider read the comments on private and unpublished posts. It is tracked as CVE-2026-66666 and has a score of 6.9 out of 10 (medium severity) on the CVSS scale. According to the CVE record, versions 6.6 to 7.1.2 are affected, but the same fix has also been applied to older branches. No CVE numbers have been published for the other six issues so far.

The good news is that, so far, there is no public information about these vulnerabilities being used in attacks. They were reported responsibly by independent researchers and companies, including Anthropic (three of the seven), Trail of Bits, Patchstack and members of the WordPress Security Team. Updating to 7.1.3 removes the risk completely, so it is all you need to do to stay safe.

Full details are available in the official WordPress announcement and the version 7.1.3 release notes.

What else was fixed

Beyond security, WordPress 7.1.3 also includes 4 bug fixes. The block editor was not changed this time. This is what matters for site owners:

  • Fatal error when uploading images. On some servers without PHP's DOM extension, uploading an image caused a crash. The problem came from a new WordPress 7.1 feature that reads the alt text embedded in images. This is the most important fix on the list.
  • The site icon in the top bar. The icon now has a fixed size and no longer breaks the top bar (admin bar).
  • ReverbNation embeds. The address WordPress uses to embed content from the music platform ReverbNation has been updated so that it keeps working.
  • Someecards embeds. someecards.com is no longer one of the sources WordPress embeds content from automatically.

The security fixes also bring two changes worth knowing about:

  • Imgur is no longer a trusted embed source. Embedded Imgur images and albums may therefore look different. According to Patchstack, the update does not clear embeds that are already stored, so if you have any, it is worth reviewing them.
  • Custom-built plugins. If you use a plugin built specifically for you that works with non-standard content types, check that everything works normally after the update.

Is my site affected?

How many of the vulnerabilities affect a site depends on its version. The newest versions are affected the most, and fixes are available for every branch from 4.7 onwards:

WordPress version Affected? What to do
7.1.3 No No action needed
7.1, 7.1.1 and 7.1.2 Yes, by all 7 vulnerabilities Update to 7.1.3
6.5 to 7.0.x Yes, by 6 vulnerabilities (not the pending-comments one) Update to 7.1.3
4.7 to 6.4.x Yes, by some of them (not the pending-comments or export ones) Update to 7.1.3
4.6 and older Probably, and no longer receives fixes Contact us about a migration

Please note that updating to 7.1.2 in September is not enough. Version 7.1.2 is affected by all 7 vulnerabilities.

If for some reason you cannot move to 7.1.3 right away, WordPress has also released fixes for older branches, such as 7.0.7, 6.9.10 and 6.8.11, all the way down to 4.7.38. They are already available. This is a good temporary solution, but it does not replace updating to the current version.

By default, WordPress automatic updates stay within the same branch. That means a site on 7.1.2 will update itself to 7.1.3, and a site on 7.0.6 to 7.0.7, not to 7.1.3. If you want the latest version, update manually.

If you are not sure which version you are running, you can find it in the WordPress admin area, in the bottom right corner of the screen, or under Dashboard → Updates.

Why you should act now

Now that the fixes are public, information about the vulnerabilities is available to attackers too, and sites that have not been updated can become targets of automated attacks. The comment issues are especially attractive for such attacks, because they do not require an account and the comment form is open on most sites. The good news is that updating takes only a few minutes and removes the risk completely.

What to do

Updating WordPress takes only a few minutes. Follow these simple steps:

  1. Back up your site. This is good practice before any update.
  2. Log in to your WordPress admin area.
  3. Go to Dashboard → Updates.
  4. If an update is available, click Update Now.
  5. Check that your version is now 7.1.3.

In many cases WordPress applies important security updates automatically, but it is worth checking manually so you can be sure your site is protected.

While you are in the admin area, take a few more minutes for three things:

  • Comments → Pending. Do not click links in comments, especially if your site is not updated yet. Delete comments that look suspicious.
  • Users → All Users. Most of these vulnerabilities require an account on the site. Remove accounts that are no longer in use, and lower the others to the role they actually need.
  • Cache. If you use a caching plugin, clear the cache after updating so visitors see the updated version of your pages.

Need help?

If you are not sure which version you are running, have trouble updating, or simply want someone to check that everything is fine, the Jump.bg support team is here for you. Contact us and we will guide you step by step.

If you are still choosing where to host your site, take a look at our WordPress hosting plans. They are fast, secure and come with expert support, so you can focus on your business.

Your site's security matters to us. If you have any questions, get in touch with the Jump.bg team. We are here to help.

Enjoyed the article? Share it:
Георги Димитров
Article from

Георги Димитров

Георги Димитров прекарва над 10 години в това да прави сайтовете бързи, сигурни и надеждни. Помогнал е на десетки български и международни компании да изградят успешни онлайн проекти, от малки електронни магазини до сложни уеб приложения. В блога на Jump.bg пише за WordPress без излишен технически жаргон, с практични съвети за сигурност, производителност и поддръжка, еднакво полезни за начинаещи и за професионалисти.

More articles

Follow us:

Subscribe to our newsletter

With your subscription, you get more up-to-date news and our special promo offers

Subscribe to our newsletter