Skip to content

The publication for web craftspeople Thursday, 8 October 2026

Security

WordPress 7.1.3 Patches Seven Flaws, Three Flagged by Anthropic

WordPress 7.1.3, released October 6, 2026, fixes seven security flaws and four bugs; an immediate update is recommended. Three of the flaws were reported by Anthropic, alongside researchers from Trail of Bits and Patchstack.

WordPress 7.1.3 shipped on October 6, 2026. This maintenance and security release fixes seven flaws and four bugs, and the security team recommends updating affected sites immediately. One detail stands out: three of the seven flaws were reported by Anthropic, alongside independent researchers and Patchstack.

A maintenance release, not a major version

7.1.3 continues the tight run of fixes that followed 7.1.1 (September 17, eleven flaws) and 7.1.2 (September 22, one critical path-traversal flaw). It changes no core feature; it closes seven security holes and repairs four bugs found since the previous release.

The flaws it fixes

ComponentFlaw typeReported by
Comments admin pageStored XSS, exploitable via pending commentsThomas Chauchefoin, Trail of Bits
WP_Http::make_absolute_url()Denial of serviceAnthropic
WXR exportSecond-order SQL injectionAnthropic
Author rolePrivilege escalation (sticking posts)Anthropic
Private and unpublished commentsUnauthenticated disclosureAnanda Dhakal, Patchstack
Imgur embedsXSSZhengyu Liu, Jingcheng Yang, Gavin Zhong
{status}_{type} hooksAction-name collision via forgeable parametersAlex Concha, WordPress security team

Why Anthropic’s involvement stands out

Three of the seven reports in this release carry the credit “reported by Anthropic,” with no public detail on the detection method. Beyond this specific case, that presence confirms a trend already visible elsewhere in the ecosystem: AI labs are becoming regular reporters of vulnerabilities in codebases as exposed as WordPress core, alongside the usual human researchers like Trail of Bits or Patchstack.

Updating without drama

Sites with background updates enabled receive 7.1.3 automatically. Everyone else can update from the dashboard (Updates → Update Now) or from the command line:

wp core update --version=7.1.3
wp core verify-checksums

Two of the seven fixes touch the comment-moderation stack (the admin page and the visibility of private comments). On a site that heavily customizes that area through a third-party plugin, a staging pass before going live limits unpleasant surprises.

Backward compatibility and backports

As a courtesy, security fixes are backported to every branch still eligible, down to 4.7. Only the latest version of WordPress remains actively supported; backports ship as they become ready.

Only the latest version of WordPress is actively supported; older fixes are backported as a courtesy, not an obligation.

What to remember

Seven flaws and four bugs fixed on October 6, three of them reported by Anthropic: updating to 7.1.3 should be treated as a priority, especially on sites with heavily customized comment moderation. Versions back to 4.7 will receive matching backports as they’re ready.

I’d stop treating these 7.1.x releases as minor housekeeping: three fixes in under three weeks is a pace that warrants background auto-updates turned on by default on every production site, paired with hardening the login screen rather than simple trust in the backport cycle — Simon Janvier.

Further reading: the official announcement on WordPress.org.

Read next