Skip to content
WordPress 7.1.1 Security Release Addresses 11 Vulnerabilities

WordPress 7.1.1 Security Release Addresses 11 Vulnerabilities

First seen 18 Sep 2026, 19:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 21:53 UTC
  • WordPress 7.1.1 fixes 11 security vulnerabilities.
  • Affected versions include 6.5 to 7.0; updates are critical.
  • Stored XSS and information disclosure are key vulnerabilities.

On September 18, 2026, WordPress released version 7.1.1, a security and maintenance update addressing 11 vulnerabilities. The update includes 17 bug fixes for Core and 19 for the Block Editor. Notable vulnerabilities include stored cross-site scripting (XSS) issues and an information disclosure flaw. The vulnerabilities were reported by various security researchers, including Rafie Muhammad and Jeremy Felt. Affected versions include WordPress 6.5 to 7.0, with patches available for these older versions. Users are urged to update immediately to mitigate risks. The security team emphasized the importance of these fixes due to the potential for exploitation. The next major release, version 7.2, is planned for December 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
WordPress 7.1.1 released
This version includes 11 security fixes and 36 bug fixes overall, addressing vulnerabilities reported by various researchers.
wordpress.org
2026-09-18
Security vulnerabilities disclosed
The vulnerabilities include stored XSS and information disclosure issues, affecting multiple versions of WordPress.
wordpress.org

More articles in this cluster (2)