The latest security release for WordPress, 7.1.1, is available on Pantheon.
Action required
Because this is a security update, we recommend all users upgrade to WordPress 7.1.1 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.
Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of some of these vulnerabilities, and are actively monitoring those rules. This includes an unauthenticated stored cross-site scripting vulnerability (CVE-2026-93485), reported through Patchstack's Vulnerability Disclosure Program, which was already covered by these mitigations ahead of the release. However, customers need to update their sites as soon as possible.
Highlights
This release resolves 11 security vulnerabilities, most requiring an authenticated role (Contributor or above) to exploit. WordPress has not assigned CVE identifiers to these issues.
For full details, see the WordPress 7.1.1 release notes and WordPress documentation.