WordPress shipped version 7.1.3 on October 6, a maintenance and security release covering seven vulnerabilities and four bugs. Jake Spurlock headed the release, and WordPress.org urges site owners to update immediately. For any team whose organic traffic runs through a WordPress install, this patch belongs at the top of the queue.
WordPress.org credits the seven security fixes to a mix of outside researchers and its own security team:
- Anthropic reported three: a denial-of-service problem in the
WP_Http::make_absolute_url()method, a second-order SQL injection in the WXR export tool, and a gap that let Author-level users pin posts as sticky. - Thomas Chauchefoin of Trail of Bits found a stored XSS in the Comments admin screen that pending comments can trigger.
- Ananda Dhakal of Patchstack found that visitors without logins could read comments attached to private and unpublished content.
- Zhengyu Liu, Jingcheng Yang, and Gavin Zhong reported an XSS weakness in Imgur embeds.
- Alex Concha of the WordPress security team reported that forgeable parameters in the
{status}_{type}hook could produce an action name collision.
Search Engine Journal, in a report by Roger Montti published the same day, noted what the announcement leaves out. WordPress.org gave no severity ratings or CVSS scores, offered no technical detail on the flaws, and said nothing about active exploitation. That gap matters. Without scores, teams cannot rank this release against other work and have to treat all seven as in scope.
Older branches are covered too. WordPress.org says it is porting the fixes to each branch still eligible for security patches, currently reaching back to 4.7, and that each port will ship when ready. The same notice repeats that active support extends only to the newest release. A site pinned to an old branch is waiting on a courtesy, not a commitment.
The bug side carries its own search angle. According to Search Engine Journal, two fixes address oEmbed endpoints returning 404 errors, one fixes an admin toolbar site icon that could swell to enormous size, and one is the bug Montti labels critical. On hosts lacking PHP’s DOM extension (ext-dom), code introduced in WordPress 7.0 could throw a fatal error during image uploads and halt them entirely. Montti reports that the WordPress ticket marks the bug critical, yet a core committer suggested it was probably rare, because the code had been out for 134 days before the first report. The word “critical” there comes from the ticket and Search Engine Journal, not from a security score.
Why does a CMS patch belong in an SEO workflow? Because a compromised WordPress site becomes a search problem fast. Stored XSS and SQL injection are the kinds of flaws attackers use to plant injected spam pages or alter published content, and cleaning that up means lost crawl trust, rewritten pages, and Search Console warnings to chase. WordPress.org has not said these specific flaws are being used that way. The point is the failure mode, not a confirmed incident. A broken upload pipeline is a quieter version of the same issue: editors cannot publish images, and content calendars slip.
A practical routine keeps this contained. Take a backup, then update staging first and confirm the dashboard, comments screen, and WXR export still work. Push the update to production and check that auto-updates are actually enabled, since WordPress.org says supported sites will update in the background. Confirm in Site Health that the DOM extension is loaded, and upload a test image. Then scan Search Console for new URLs you did not create, review recently edited posts, and check pending comments for odd markup.
Google has not said it treats outdated WordPress versions as a ranking factor, and this release does not change that. The risk runs through what attackers or failed uploads do to your pages. Teams on branches older than the current release should treat the backport timeline as unknown and plan a move to the latest version.
Based on the WordPress.org announcement “WordPress 7.1.3 Maintenance and Security Release” (October 6, 2026) and Search Engine Journal’s report by Roger Montti (October 6, 2026).