On October 6, 2026, WordPress 7.1.3 was released to the public.
To get this version, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/releases/.
For step-by-step instructions on installing and updating WordPress:
If you are new to WordPress, we recommend that you begin with the following:
This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
WP_Http::make_absolute_url() method, reported by Anthropic{status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security teamAs a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.
/wp-admin/js/common.js /wp-admin/includes/export.php /wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php /wp-includes/class-wp-customize-manager.php /wp-includes/class-wp-customize-setting.php /wp-includes/class-wp-http.php /wp-includes/class-wp-oembed.php /wp-includes/class-wp-query.php /wp-includes/post.php
No package was revised.
An update on the Presence API feature plugin, announced in April. Here’s everything that’s shipped…
This security release features a fix for a critical severity security vulnerability. Because this is…
The full chat log is available beginning here on Slack. WordPress Performance Trac tickets @westonruter…
I’m happy to announce that I am now serving as president of the Open Website…
This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for…
The full chat log is available beginning here on Slack. WordPress Performance Trac tickets @spacedmonkey…