Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting, SQL injection, information disclosure, and other security weaknesses.

The project recommends immediate updates, with fixes also available for older affected branches. Only the latest WordPress version remains actively supported.

The release documentation lists seven security issues, although its introductory sentence describes “one security fix.” It provides no CVE identifiers, severity scores, or confirmed exploitation details. Consequently, the headline’s critical wording should not be interpreted as an official severity classification for every vulnerability.

One vulnerability involves stored cross-site scripting on the Comments administration page. Pending comments provide the attack surface, potentially exposing administrators when they review submitted content.

Thomas Chauchefoin of Trail of Bits reported this issue. The disclosure does not describe the malicious payload or precise conditions required for successful exploitation.

A separate cross-site scripting weakness affects Imgur embeds. WordPress credits Zhengyu Liu, Jingcheng Yang, and Gavin Zhong with reporting it.

These two findings concern different content pathways: comment moderation and embedded media. Both make the update relevant to sites that process user content or display externally sourced material.

WordPress Vulnerabilities

Anthropic reported a second-order SQL injection vulnerability in WordPress WXR export. The release identifies the export component but does not explain the injection sequence, required permissions, or database impact.

Administrators should therefore avoid assuming that the issue enables unrestricted database access or that every export operation is exploitable. Another vulnerability allows unauthenticated disclosure of comments associated with private and unpublished posts.

Reported by Ananda Dhakal of Patchstack, this issue affects information expected to remain outside public access. The announcement identifies comments as the exposed data it does not claim that attackers can retrieve complete private posts.

Anthropic also reported a weakness that lets users with the Author role make posts sticky. This represents an authorization problem involving a publishing capability.

Separately, Alex Concha of the WordPress security team reported forgeable parameters passed to the {status}_{type} hook that can produce action name collisions. The announcement leaves the broader exploitation consequences unspecified.

A denial-of-service issue affects the WP_Http::make_absolute_url() method. Anthropic reported this finding as well, but WordPress provides no request pattern, resource-consumption measurements, or detailed attack prerequisites in the release notes.

Administrators can install WordPress 7.1.3 through Dashboard > Updates or obtain it from the official releases page. WordPress explicitly recommends updating sites immediately because this is a security release. Older affected branches also receive these fixes, but that doesn’t change the project’s stated support policy.

The revised files span administration JavaScript, export handling, REST posts, customization, HTTP processing, embeds, queries, and post operations. No packages were revised.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks appeared first on Cyber Security News.