ZeroHour
Product

WordPress 7.1.1

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal

WordPress 7.1.1 patches 11 core vulnerabilities, including stored XSS in wpautop() and an authenticated path traversal in the REST Templates Controller reported by Anthropic.

WordPress released 7.1.1, a short-cycle maintenance and security update fixing 11 vulnerabilities across core, themes, REST API, comments, XML-RPC, and plugin management, plus 17 core and 19 Block Editor bug fixes. The most notable flaw is a stored XSS in wpautop() where unauthenticated commenters can inject script that executes when a moderator approves the comment, potentially enabling admin session theft. Anthropic reported an authenticated path traversal in the WP REST Templates Controller and an authorization flaw letting low-privileged users overwrite posts outside their scope. Security fixes are backported to supported branches through WordPress 4.7, and WordPress 7.2 is expected in December.

WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities

WordPress 7.1.1 fixes 11 core vulnerabilities including stored XSS, path traversal, and authorization bypass flaws; admins urged to update immediately.

WordPress released version 7.1.1, a security and maintenance update fixing 11 vulnerabilities including multiple stored XSS flaws, an authenticated path traversal in the WP REST Templates Controller reported by Anthropic, missing authorization checks, and an XML-RPC issue bypassing edit_css checks. The release also includes 17 core bug fixes and 19 Block Editor fixes, with security fixes backported to supported branches through 4.7. No exploitation is reported; administrators are urged to update immediately or rely on automatic background updates.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.