WordPress released 7.1.1, a maintenance and security update that remediates 11 vulnerabilities alongside 17 Core and 19 Block Editor bugs. The flaws include stored cross-site scripting, authorization weaknesses and bypasses, authenticated path traversal, arbitrary post overwrite, private-information disclosure, unauthorized comment reparenting, XML-RPC capability-check bypasses, and unauthorized installation or previewing of inactive WordPress.org themes through crafted URLs. Specific fixes also address script injection via wpautop(), custom-header theme XSS, and HTML API comment-context escaping.
Administrators should update production sites to WordPress 7.1.1 immediately; sites configured for automatic background updates are expected to receive the release automatically. Applicable fixes are being backported to supported WordPress security branches through version 4.7. Tenable published a Nessus detection plugin for installations from WordPress 7.0.0 through versions before 7.1.1, although its metadata reported no known public exploits.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
WordPress released version 7.1.1, fixing 11 security vulnerabilities as well as 17 Core bugs and 19 Block Editor bugs. The fixes include stored XSS, authorization flaws, authenticated path traversal, arbitrary post overwrite, information disclosure, and unauthorized comment reparenting; WordPress urged administrators to update immediately and said applicable fixes would be backported through supported branch 4.7.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcewordpress.org
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.