WordPress 7.1.3
OK WORDPRESS 7.1.3 JUST DROPPED AND ITS A SECURITY RELEASE PERIOD. You update right away or dont, but the WordPress team literally says update immediately. Its 7 security fixes and 4 bug fixes in one patch. Go.
The Security Fixes
- Stored XSS on the Comments administration page, exploitable via pending comments. Reported by Trail of Bits.
- DoS in WP_Http::make_absolute_url(). Reported by Anthropic.
- Second-order SQL injection in WordPress WXR export. Reported by Anthropic.
- Weakness letting Author role users sticky posts. Reported by Anthropic.
- Unauthenticated disclosure of comments on private and unpublished posts. Reported by Patchstack.
- Imgur embeds vulnerable to XSS.
- Forgeable parameters passed to the {status}_{type} hook can lead to action name collision.
Why It Matters
The stored XSS and the unauthenticated comments disclosure are the ones that scare me. Both need no user action to trigger. If you run a comments-open blog, seriously go update now period. Automatic background updates should handle it, but check your dashboard and hit Update Now.
How To Get It
Grab the zip from wordpress.org or go to Dashboard and Updates then Update Now. Release was led by Jake Spurlock. Seven fixes, four bug fixes, zero excuses. Update rn.