WordPress 7.1.3 Released: Fixes Seven Security Vulnerabilities, Including Three Found by Anthropic
WordPress has released version 7.1.3, patching seven security vulnerabilities in its platform core and resolving four software bugs. Notably, three of the security vulnerabilities were identified and reported by the AI research company Anthropic. This update underscores the expanding role of AI organizations in cybersecurity research and vulnerability detection. It also critical for WordPress administrators to update immediately to prevent potential attacks like stored cross-site scripting and unauthorized privilege escalation. The most easily exploitable flaw is a stored XSS vulnerability in the comment moderation queue reported by Trail of Bits, which triggers when an admin opens the pending comments page. Anthropic discovered a flaw in the WXR exporter that could impact database queries, a denial-of-service issue in `WP_Http::make_absolute_url()`, and an authorization issue allowing author-level users to pin posts.
## BACKGROUND
Cross-Site Scripting (XSS) is a prevalent web vulnerability where malicious code is injected into a site and executed in a user's browser context. WordPress Extended RSS (WXR) is an XML schema used by WordPress to format and export website content such as posts, comments, and pages for migration or backup.