WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress 7.1.1 patches 11 core vulnerabilities, including stored XSS in wpautop() and an authenticated path traversal in the REST Templates Controller reported by Anthropic.
WordPress released 7.1.1, a short-cycle maintenance and security update fixing 11 vulnerabilities across core, themes, REST API, comments, XML-RPC, and plugin management, plus 17 core and 19 Block Editor bug fixes. The most notable flaw is a stored XSS in wpautop() where unauthenticated commenters can inject script that executes when a moderator approves the comment, potentially enabling admin session theft. Anthropic reported an authenticated path traversal in the WP REST Templates Controller and an authorization flaw letting low-privileged users overwrite posts outside their scope. Security fixes are backported to supported branches through WordPress 4.7, and WordPress 7.2 is expected in December.