The latest security release for WordPress, 7.1.3, is available on Pantheon.
Action required
Because this is a security update, we recommend all users upgrade to WordPress 7.1.3 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.
Pantheon has deployed a platform-wide mitigation (virtual patching via our routing network) against external abuse of the stored XSS on the Comments administration page, and is actively monitoring that rule. However, customers need to update their sites as soon as possible.
Highlights
This release resolves seven security vulnerabilities:
- A stored XSS on the Comments administration page, exploitable via pending comments.
- A DoS issue in the
WP_Http::make_absolute_url()method. - A second-order SQL injection in WordPress WXR export.
- A weakness allowing Author role users to sticky posts.
- Unauthenticated disclosure of comments on private and unpublished posts.
- Imgur embeds are vulnerable to XSS.
- Forgeable parameters passed to the
{status}_{type}hook can lead to action name collision.
For full details, see the WordPress 7.1.3 release notes and WordPress documentation.