Plate 22
WordPress 7.1.3: The Third Security Update in Three Weeks
WordPress 7.1.3 (Oct. 6) fixes seven security issues after 7.1.1 and the critical 7.1.2 in September. Patchstack's severity breakdown, the cached-embed gotcha, the new canonical MCP Adapter plugin for AI agents, and a six-step checklist for site owners and freelancers.
Aditya Challa6 min read
WordPress released version 7.1.3 on Oct. 6, 2026, with seven security fixes and four bug fixes, and the project recommends that sites "update your sites immediately." It is the third WordPress security release in under three weeks, after 7.1.1 on Sept. 17 and 7.1.2 on Sept. 22.
If you run a WordPress site, or look after a few for clients, the news is not that this release is an emergency. Patchstack says it isn't. The news is that patching has become a weekly habit, and the sites that get hurt are the ones that skip it. Here is what 7.1.3 fixes, what changed the same week for AI connections to WordPress, and a short checklist to run today.
What does WordPress 7.1.3 fix?
The WordPress.org release post lists seven security fixes, including a stored cross-site scripting (XSS) bug on the Comments admin page, a second-order SQL injection in the WXR export, a bug that let Author-role users make posts sticky, a leak of comments on private and unpublished posts to visitors who aren't logged in, and an XSS issue in Imgur embeds. Three of the seven were reported by Anthropic.
Patchstack's breakdown is the useful part for site owners. Only two of the fixes can be started by an anonymous visitor: the comment-feed leak, and the comments XSS, which also needs a moderator to click a link. Three need a Contributor or Author account, one needs an administrator to run an export, and one depends on a plugin. "Update as soon as you can, but this isn't a drop-everything emergency," Patchstack wrote.
One detail is easy to miss. Patchstack noted that the Imgur fix does not remove embed content that's already cached, so a malicious embed can keep rendering until you clear your site's cache.
Why does the pace matter?
Because the previous release was serious. WordPress 7.1.2 fixed a single core vulnerability. The Repository reported that the official advisory rated it 9.2 (critical) under CVSS 4.0, and that under certain theme and server conditions it could let an unauthenticated attacker run code. According to Patchstack, attackers started probing for it less than five hours after the fix went out.
That is the pattern to plan around. Once a patch is public, attackers can work backward from it, so the gap between "fixed" and "being exploited" is now measured in hours. Sites with automatic background updates pick up these releases on their own. Sites without them depend on someone remembering.
WordPress.org also says only the most recent version is actively supported. Fixes are being backported as a courtesy, and Patchstack reported that at the time of its post, the 4.7 to 6.5 branches were still waiting.
What changed for AI tools and WordPress this week?
Search Engine Journal reported on Oct. 7 that WordPress's MCP Adapter is now available as a canonical plugin in the official WordPress.org directory. MCP, the Model Context Protocol, is a standard way for AI agents to connect to apps, and the adapter lets them work with WordPress functions such as reading posts or updating settings.
The plugin page lists version 0.7.0, 40,000+ active installations (from its earlier GitHub releases), WordPress 6.9 or newer, and PHP 7.4 or newer. It says exposure is opt-in: an ability is only reachable over MCP if it has been marked public, the AI client authenticates as a WordPress user, and permission checks run against that user. In other words, an AI agent can do whatever its WordPress account is allowed to do, which is why the role fixes in 7.1.3 matter.
What should site owners do today?
- Check your version. Go to Dashboard, then Updates, and confirm you're on 7.1.3. If you rely on automatic background updates, check that the update actually ran.
- Clear your caches. After updating, clear page and object caches, and if you've ever embedded Imgur content, follow Patchstack's advice and clear cached embeds.
- Audit your users. Patchstack suggests reviewing who holds Contributor or higher roles, since many of these fixes are about what those roles can reach. Remove old freelancer, guest-author and test accounts.
- Give AI tools their own account. If you connect an AI agent through MCP, or use a plugin that writes or publishes for you, give it a dedicated user with the lowest role that does the job, and only expose the abilities you need.
- Get off old branches. If a site is stuck on an older WordPress version because of a plugin or theme, put the upgrade on the calendar.
- Write it down for clients. If you manage client sites, keep a simple log of the version, update date and who checked it. Our client website launch and handover checklist covers what to hand over.
Disclosure: some links are affiliate links; ShopperCove may earn a commission at no extra cost to you.
If you use an auto-publishing plugin, step 4 applies to it. AI Traffic Secrets, for example, is a WordPress plugin that its sales page says writes, illustrates, scores and publishes a 1,500+ word post every day using your own OpenAI or Anthropic Claude API key. Give a tool like that only the publishing rights it needs, and review what goes live. ShopperCove did not test it for this article. AI Traffic Secrets link: Open link (affiliate link)
If you build sites for local-service clients and some of them don't need WordPress at all, a different starting point may cut your plugin count. Ready Client Sites sells ready-made business websites, and its page states plainly that they are Node.js applications, not WordPress themes, so they need Node.js 22+ or VPS/Docker hosting, and you still own updates on that stack. ShopperCove did not test it for this article. Ready Client Sites link: Open link (affiliate link)
Tools that help
- AI Traffic Secrets, WordPress auto-blogging plugin. Per its sales page: Starter is $27 for 1 site, Professional $67 for 10 sites and Agency $97 for unlimited sites. It includes SEO meta for Rank Math, Yoast and AIOSEO, comes with a 60-day money-back guarantee, and states that nothing on the page is a guarantee of traffic, rankings or income. AI Traffic Secrets link: Open link
- Ready Client Sites, Node.js business website templates. Per its sales page: 5 sites for $97 or 15 for $247 as a one-time purchase, with a commercial-use license for client projects. Hosting and domains are not included. Ready Client Sites link: Open link
How this was made: facts were gathered on 8 Oct 2026 (IST) from the WordPress.org release pages, Patchstack, The Repository, Search Engine Journal and the MCP Adapter plugin page listed below, then written up with AI help and checked line by line against those sources. ShopperCove did not install the MCP Adapter for this article.
Sources
- Open wordpress.org
- Open wordpress.org
- Open wordpress.org
- Open patchstack.com
- Open therepository.email
- Open searchenginejournal.com
- Open wordpress.org
- Open aitrafficsecrets.com
- Open readyclientsites.com
Related
Lab evidence
What I found running this
8 Oct 2026 IST: curl GET returned 200 for both WordPress.org 7.1.3 pages, Patchstack, The Repository, SEJ, the MCP Adapter plugin page and both sales pages. Hops gave 307 to aitrafficsecrets.com and readyclientsites.com. We did not test AI Traffic Secrets ourselves; claims come from its sales page. We did not test Ready Client Sites ourselves; claims come from its sales page.
Keep reading
Next.js 15 LTS ends 21 Oct 2026: upgrade checklist
Next.js 15.x (released 21 Oct 2024) leaves Maintenance LTS on 21 Oct 2026 per nextjs.org/support-policy. Active LTS is 16.x. Points to September 2026 patches 16.3.8 / 15.5.27. No exploit steps; nothing tested; no affiliate.
Summary5 Oct 20264 min read
TanStack Start XSS: Patch CVE-2026-102989 Now
TanStack Start CVE-2026-102989: patched versions, lockfile checks, and redeploy steps from the official advisory.
News1 Oct 20264 min read
ufo vs URL: 2.4 KB vs 0.5 KB Gzip
Hands-on6 Oct 20265 min read