WordPress 7.1.3 Fixes Seven Vulnerabilities and an Image Upload Failure
WordPress 7.1.3 fixes seven vulnerabilities and a critical bug that prevented image uploads on some hosting setups. Site owners are advised to install the update.
WordPress has released version 7.1.3, fixing seven vulnerabilities and four bugs, including a critical image upload failure. As Search Engine Journal reported on October 6, 2026, WordPress recommends updating sites immediately. The upload failure could occur on hosting setups without the optional PHP DOM extension.
Seven vulnerabilities: what we know
The list includes stored XSS, a denial-of-service (DoS) issue, and a second-order SQL injection. The update also fixes an issue that allowed users with the Author role to make posts sticky, unauthenticated disclosure of comments, XSS in embedded Imgur content, and a parameter spoofing issue that could cause action name collisions.
These issues affect different parts of a site: user permissions, access to comments, and the handling of embedded content. But the vulnerability names alone are not enough to assess the risk to any individual site. The official announcement provides no detailed descriptions, severity ratings, or CVSS scores. It also does not say whether these vulnerabilities are being exploited against live sites.
So the recommendation to update immediately should not be taken to mean that all seven issues are equally dangerous or already being used by attackers. For site owners, the main takeaway is simpler: WordPress has released fixes and advises installing them without delay. There is no need to wait for more information about exploitation before updating.
Security patches are also being backported to older branches still eligible for them; that range currently extends back to WordPress 4.7. The work is not yet complete: updates for those branches will be released as they become ready. The 7.1.3 announcement does not, by itself, mean a patch is already available for every older branch.
What prevented image uploads
Of the four bugs fixed, three caused day-to-day inconveniences. Two caused oEmbed URLs to return 404 responses—one for a music promotion platform and the other for a humorous greeting card site. Another could stretch the site icon image in the admin dashboard to an enormous size.
The fourth bug was rated critical in the WordPress ticket. On hosting without the PHP DOM extension, attempting to upload an image could trigger a fatal error: the process stopped, and the file was not uploaded. This describes a failure when adding a media file, not a claim that the entire site necessarily stopped working.
The ext-dom extension provides the DOMDocument and DOMXPath classes. WordPress strongly recommends it but does not require it. Version 7.0 introduced code that called DOMDocument without checking whether the extension was available. If the hosting setup lacked it, an image upload could fail.
One core developer suggested the problem was probably rare: 134 days passed between the release of the relevant code and the first report of a failure. That interval does not tell us whether other site owners encountered the bug or why it was not reported sooner. For any given site, the deciding factor remains whether the extension is missing.
What site owners should do
The practical steps after the update announcement are straightforward:
- Install the available WordPress fix.
- If the site runs on an older branch, check whether a patch has been released for that branch specifically.
- After updating, test an image upload.
- If uploads previously ended in a fatal error, ask a technical specialist whether ext-dom is available on the hosting setup.
That last point does not mean every failed upload is caused by this bug. The reported case is specific: the code called DOMDocument where the extension was missing. Checking for it helps distinguish this issue from other possible causes of upload failures.
My take: the patch and everyday work
I make custom furniture and handle enquiries through a small website. For a site owner, an upload problem often becomes noticeable only when it is time to change the photos of completed work. At that point, “fatal error” sounds more alarming than the outcome described here: the file cannot be added, but the report does not say the entire site stopped loading.
In my view, the apparent rarity of this bug is no reason to delay the update. The same release fixes seven vulnerabilities, and WordPress recommends installing the patch immediately. I would update the site and then test a familiar task—adding a photo. That makes it easier to see whether the fix has helped with the work the site is there to do.
Sources
Where the news comes from. The text is a retelling in the author’s own words; the facts come from the source, the opinion is the author’s.
- WordPress 7.1.3 Fixes 7 Vulnerabilities And 1 Critical Flaw via @sejournal, @martinibuster www.searchenginejournal.com
Furniture workshop owner
I make custom furniture in Tashkent and manage inquiries through a small website. When choosing a CMS, think about who will update photos and prices a year from now, not just what the site looks like at launch.
All posts by the authorRelated articles
Next.js Releases Security Updates for Versions 15.5 and 16.3
Next.js has released versions 16.3.8 and 15.5.27 to fix vulnerabilities involving caching, information disclosure, and image optimization. Teams are advised to update their apps and check which features they use.
Breach of .gh, .sl and .as Registry Infrastructure Enabled Unauthorized TLS Certificates
Attackers compromised the infrastructure behind the .gh, .sl and .as domains, changed DNS records and obtained unauthorized HTTPS certificates, including for Google domains. Google blocked them in Chrome and advises site owners to check CT logs.
Google Warns Site Owners About Fake Content Authors
Google has added a warning about fake authors to its guidance for site owners. Editorial teams should check author names, photos, and credentials for accuracy.
Discussion 5
Nika Beridze
We ran into the image-upload issue on our café site when moving between hosting setups—turns out the optional PHP DOM extension wasn’t enabled. I’m adding this update to our next maintenance checklist; a failed product photo upload is a surprisingly annoying way to discover a server dependency 😅
Davit Vashakidze
@nika.cafe a missing DOM extension can stall product photos right before an order update, so I’ll add that check to our hosting handover list too
Ruslan Fazylov
Nothing like discovering a server dependency when the product photos are already due. Adding the DOM check to the handover list is cheaper than explaining a delayed order update.
Jonas Vogel
That’s a good handover item, especially since the DOM extension is optional and can be easy to miss when a host changes. I’ve learned the hard way that a quick check of PHP extensions before launch saves a lot of scrambling when someone needs to upload an image on a deadline.
Ulvi Yadigarov
@davit.vashakidze good call — I’d also note the PHP DOM requirement in the handover docs, not just the checklist, so it’s easier to catch before a hosting migration. A quick test upload after the move could save someone from finding out when they’re trying to update product photos 😅