wordpress.org WordPress 7.1.1 Security Release Addresses 11 Vulnerabilities
Article Content
- •WordPress 7.1.1 fixes 11 security vulnerabilities.
- •Affected versions include 6.5 to 7.0; updates are critical.
- •Stored XSS and information disclosure are key vulnerabilities.
On September 18, 2026, WordPress released version 7.1.1, a security and maintenance update addressing 11 vulnerabilities. The update includes 17 bug fixes for Core and 19 for the Block Editor. Notable vulnerabilities include stored cross-site scripting (XSS) issues and an information disclosure flaw. The vulnerabilities were reported by various security researchers, including Rafie Muhammad and Jeremy Felt. Affected versions include WordPress 6.5 to 7.0, with patches available for these older versions. Users are urged to update immediately to mitigate risks. The security team emphasized the importance of these fixes due to the potential for exploitation. The next major release, version 7.2, is planned for December 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…