WordPress 7.1.3 shipped on October 6, 2026. This maintenance and security release fixes seven flaws and four bugs, and the security team recommends updating affected sites immediately. One detail stands out: three of the seven flaws were reported by Anthropic, alongside independent researchers and Patchstack.
A maintenance release, not a major version
7.1.3 continues the tight run of fixes that followed 7.1.1 (September 17, eleven flaws) and 7.1.2 (September 22, one critical path-traversal flaw). It changes no core feature; it closes seven security holes and repairs four bugs found since the previous release.
The flaws it fixes
| Component | Flaw type | Reported by |
|---|---|---|
| Comments admin page | Stored XSS, exploitable via pending comments | Thomas Chauchefoin, Trail of Bits |
WP_Http::make_absolute_url() | Denial of service | Anthropic |
| WXR export | Second-order SQL injection | Anthropic |
| Author role | Privilege escalation (sticking posts) | Anthropic |
| Private and unpublished comments | Unauthenticated disclosure | Ananda Dhakal, Patchstack |
| Imgur embeds | XSS | Zhengyu Liu, Jingcheng Yang, Gavin Zhong |
{status}_{type} hooks | Action-name collision via forgeable parameters | Alex Concha, WordPress security team |
Why Anthropic’s involvement stands out
Three of the seven reports in this release carry the credit “reported by Anthropic,” with no public detail on the detection method. Beyond this specific case, that presence confirms a trend already visible elsewhere in the ecosystem: AI labs are becoming regular reporters of vulnerabilities in codebases as exposed as WordPress core, alongside the usual human researchers like Trail of Bits or Patchstack.
Updating without drama
Sites with background updates enabled receive 7.1.3 automatically. Everyone else can update from the dashboard (Updates → Update Now) or from the command line:
wp core update --version=7.1.3
wp core verify-checksums
Two of the seven fixes touch the comment-moderation stack (the admin page and the visibility of private comments). On a site that heavily customizes that area through a third-party plugin, a staging pass before going live limits unpleasant surprises.
Backward compatibility and backports
As a courtesy, security fixes are backported to every branch still eligible, down to 4.7. Only the latest version of WordPress remains actively supported; backports ship as they become ready.
Only the latest version of WordPress is actively supported; older fixes are backported as a courtesy, not an obligation.
What to remember
Seven flaws and four bugs fixed on October 6, three of them reported by Anthropic: updating to 7.1.3 should be treated as a priority, especially on sites with heavily customized comment moderation. Versions back to 4.7 will receive matching backports as they’re ready.
I’d stop treating these 7.1.x releases as minor housekeeping: three fixes in under three weeks is a pace that warrants background auto-updates turned on by default on every production site, paired with hardening the login screen rather than simple trust in the backport cycle — Simon Janvier.
Further reading: the official announcement on WordPress.org.
