ZeroHour
Product

WP REST Templates Controller

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal

WordPress 7.1.1 patches 11 core vulnerabilities, including stored XSS in wpautop() and an authenticated path traversal in the REST Templates Controller reported by Anthropic.

WordPress released 7.1.1, a short-cycle maintenance and security update fixing 11 vulnerabilities across core, themes, REST API, comments, XML-RPC, and plugin management, plus 17 core and 19 Block Editor bug fixes. The most notable flaw is a stored XSS in wpautop() where unauthenticated commenters can inject script that executes when a moderator approves the comment, potentially enabling admin session theft. Anthropic reported an authenticated path traversal in the WP REST Templates Controller and an authorization flaw letting low-privileged users overwrite posts outside their scope. Security fixes are backported to supported branches through WordPress 4.7, and WordPress 7.2 is expected in December.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.