{"id":12123,"date":"2026-10-07T14:42:18","date_gmt":"2026-10-07T14:42:18","guid":{"rendered":"https:\/\/justfineinfotech.com\/wordpress-7-1-3-fixes-7-vulnerabilities-and-1-critical-flaw\/"},"modified":"2026-10-07T14:42:18","modified_gmt":"2026-10-07T14:42:18","slug":"wordpress-7-1-3-fixes-7-vulnerabilities-and-1-critical-flaw","status":"publish","type":"post","link":"https:\/\/justfineinfotech.com\/fr\/wordpress-7-1-3-fixes-7-vulnerabilities-and-1-critical-flaw\/","title":{"rendered":"WordPress 7.1.3 Fixes 7 Vulnerabilities And 1 Critical Flaw"},"content":{"rendered":"<p>WordPress announced a security release to address seven security vulnerabilities plus four bug fixes. This security release, Version 7.1.3, addresses a stored XSS, denial-of-service DoS and five other vulnerabilities of undisclosed severity level. WordPress recommends updating sites immediately<\/p>\n<h2>Seven Vulnerabilities<\/h2>\n<p>WordPress names seven vulnerabilities:<\/p>\n<ol>\n<li>Stored XSS<\/li>\n<li>DoS issue<\/li>\n<li>Second-Order SQL injection<\/li>\n<li>Weakness allowing Author role users to sticky posts<\/li>\n<li>Unauthenticated disclosure of comments<\/li>\n<li>Imgur embeds vulnerable to XSS<\/li>\n<li>Forgeable parameters that can lead to action name collision<\/li>\n<\/ol>\n<p>The official announcement does not list severity ratings, CVSS scores,describe the vulnerabilities, or offer information of whether these vulnerabilities are being exploited in the the wild. However, WordPress recommends updating immediately<\/p>\n<p>The security fixes are also being backported to older WordPress branches eligible for security fixes, currently extending through WordPress 4.7, although those backports are still in progress. Backports will ship for older branches as they become ready<\/p>\n<h2>Bug Fixes<\/h2>\n<p>The four bug fixes include three relatively benign issues that cause a poor user experience plus one that is critical<\/p>\n<p>Two of the bug fixes address oEmbed endpoints that return a 404 message. One is related to a music promotion platform and the other an eCard humor site.\u00a0One of the fixes addresses a bug that may cause a website icon image in the admin to toolbar expand to gigantic proportions. The fourth can lead to a fatal error that sounds bad but probably isn\u2019t that bad<\/p>\n<h2>Critical Flaw Leads To Fatal Error<\/h2>\n<p>The fourth is a critical WordPress bug can make image uploads fail with a fatal error on hosts lacking an optional DOM library, leaving site owners unable to upload media. The WordPress ticket for this issue says that the image upload process stopped completely, so the image could not be uploaded. That sounds less bad than a complete page or site failure<\/p>\n<p>The missing component is PHP\u2019s DOM extension (ext-dom), which provides the DOMDocument and DOMXPath classes WordPress was trying to use. The reason this problem may have arisen is that WordPress strongly recommends the extension but does not require it<\/p>\n<p>WordPress 7.0 introduced code that used DOMDocument without first checking whether the extension existed. On hosts without it, image uploads could trigger a fatal error and fail completely<\/p>\n<p>The WordPress ticket for this issue rates the bug as critical, but a core committer also indicated it was probably rare: the code had been released for 134 days before the first report, which implies that nearly all hosts already provide the DOM extension and that the critical flaw is not widespread<\/p>\n<p>Official announcement here<\/p>\n<p>Featured Image by Shutterstock\/Yes058 Montree Nanta<\/p>\n<p>CategoryNewsWordPress<\/p>\n<div style=\"clear:both;margin:30px 0 15px 0\">\n<p>\n    <strong>En rapport:<\/strong><br \/>\n    <a href=\"https:\/\/yoursite.com\/automation-training-benin\/\" title=\"Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026\" target=\"_blank\" rel=\"noopener\"><br \/>\n      Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026<br \/>\n    <\/a>\n  <\/p>\n<p>\n    &lt;a href=&quot;https:\/\/yoursite.com\/automation-africa\/&quot; title=&quot;<a href=\"https:\/\/justfineinfotech.com\/fr\/the-cost-of-a-whatsapp-conversation-is-changing-your-strategy-should-too\/\" title=\"The cost of a WhatsApp conversation is changing. Your strategy should too\">WhatsApp<\/a> Marketing Automation Africa : 6 erreurs dangereuses commises par les marques au Nig\u00e9ria\u201d&gt;<br \/>\n      Automatisation du marketing WhatsApp en Afrique\u00a0: 6 erreurs dangereuses commises par les marques au Nig\u00e9ria<br \/>\n    <\/a>\n  <\/p>\n<\/div>\n<div style=\"clear:both;margin:30px 0;padding:25px;background:#f8f9fc;border:1px solid #ddd;border-radius:8px;text-align:center\">\n<h3>Vous souhaitez apprendre cela de mani\u00e8re pratique ?<\/h3>\n<p>Rejoindre <strong>Justfine Infotech<\/strong> et d\u00e9velopper de v\u00e9ritables comp\u00e9tences num\u00e9riques en IA, automatisation, d\u00e9veloppement web, marketing digital, bureautique, e-commerce, travail ind\u00e9pendant et <a href=\"https:\/\/justfineinfotech.com\/fr\/mistral-ai-new-model-beats-chinese-competitors-in-cybersecurity-claims-ceo\/\" title=\"Le nouveau mod\u00e8le de Mistral AI surpasse ses concurrents chinois en cybers\u00e9curit\u00e9, affirme son PDG.\">cybers\u00e9curit\u00e9<\/a>.<\/p>\n<p><strong>Available <a href=\"https:\/\/justfineinfotech.com\/fr\/expanding-the-cyber-verification-program\/\" title=\"Expanding the Cyber Verification Program\">Program<\/a>mes:<\/strong><br \/>\n  Certificat de 6 semaines \u2022 Certificat professionnel de 3 mois \u2022 Dipl\u00f4me de 6 mois \u2022 Dipl\u00f4me professionnel complet<\/p>\n<p><strong>WhatsApp :<\/strong><br \/>\n  +229 01 57 57 99 15<br \/>\n  +229 01 66 68 11 60<\/p>\n<p><a href=\"https:\/\/api.whatsapp.com\/send?phone=2348132690270&amp;text=Hello\" target=\"_blank\" rel=\"noopener\">Inscrivez-vous d\u00e8s maintenant<\/a><\/p>\n<\/div>\n<p class=\"ani-source\">Source: <a href=\"https:\/\/www.searchenginejournal.com\/wordpress-7-1-3-fixes-7-vulnerabilities-and-1-critical-flaw\/592109\/\" target=\"_blank\" rel=\"nofollow noopener\">www.searchenginejournal.com<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>WordPress announced a security release to address seven security vulnerabilities plus four bug fixes. This security release, Version 7.1.3, addresses a stored XSS, denial-of-service DoS and five other vulnerabilities of undisclosed severity level. WordPress recommends updating sites immediately<\/p>","protected":false},"author":1,"featured_media":12125,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[72],"tags":[2141,433,2142,1900,188],"class_list":["post-12123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress-seo-smart-websites","tag-critical","tag-fixes","tag-flaw","tag-vulnerabilities","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/12123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/comments?post=12123"}],"version-history":[{"count":1,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/12123\/revisions"}],"predecessor-version":[{"id":12124,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/12123\/revisions\/12124"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media\/12125"}],"wp:attachment":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media?parent=12123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/categories?post=12123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/tags?post=12123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}