WordPress site owners are being told to update right away after the project shipped version 7.1.1, a release that carries 11 security fixes alongside 17 bug fixes in Core and 19 in the Block Editor. The update is available now from WordPress.org, or through the dashboard by opening Updates and clicking Update Now; sites with automatic background updates enabled will start the process on their own.
The security list covers a range of flaws. Among them are a stored cross-site scripting issue in wpautop() that could let an unauthenticated visitor inject script, subject to comment approval, and a stored XSS problem in some themes that support custom headers. The release also closes an authenticated path traversal in the WP REST Templates Controller and an arbitrary post overwrite available to Contributor-level users and above.
Other fixes address XML-RPC being used to publish customize_changeset posts that bypass edit_css checks, a missing read_post check in attachment_submitbox_metadata() that leaks a private parent-post title, and a missing authorization check that disclosed draft or pending post slugs to Contributors and above. Any authenticated user could previously reparent comments, including notes, and specially crafted URLs could automatically install and preview an inactive theme from WordPress.org. A site administrator could also network-activate an installed Network-only plugin.
Credit for the reports is split between outside researchers and the project's own staff. Jeremy Felt and Ben Bidner, both from the WordPress Security Team, flagged three of the issues between them, while Anthropic was credited with two and Rafie Muhammad of Awesome Motive, Inc. reported the wpautop() flaw.
WordPress 7.1.1 is a short-cycle release, and the next major version, 7.2, is currently planned for December. Security fixes are also being backported where necessary to every branch still eligible for them, which currently reaches back through 4.7; those backports are in progress and will ship as they become ready. Only the most recent version of WordPress is actively supported.
It is the latest in a run of security updates. Version 7.0.4 arrived in August with a single security fix, following 7.0.3 earlier that month with several. July's 7.0.2 addressed one critical and one high severity issue, and the team enabled forced updates through the auto-update system for affected sites because of the severity. The 7.1 branch itself, code-named "Mary Lou" after jazz pianist Mary Lou Williams, landed on August 19.
What the announcement does not include is a severity rating for any of the 11 flaws, or a count of how many sites remain on versions old enough to need the backports.













