WordPress released version 7.1.3 on October 6, fixing seven security vulnerabilities in the platform's core and addressing four program bugs at the same time. Interestingly, one of the reporting parties was an unusual name—Anthropic, a company primarily focused on building large models, contributed three of them. This means that a company working on cutting-edge AI is now acting as a security guard for the world's most popular content management system.
Looking at the sources of the vulnerabilities, the lineup is quite diverse. Out of the seven security vulnerabilities, Anthropic reported three, while Trail of Bits and Patchstack each reported one. One was submitted by three independent researchers together, and the last one was discovered by the WordPress security team itself. In other words, even the maintenance team only found one of them, and the rest were all monitored by external eyes.
The most dangerous one was hidden in the comment management interface, a stored cross-site scripting (XSS) issue identified by Thomas Chauchefoin from Trail of Bits. Its trickiness lies in its stealth: malicious scripts quietly enter the queue of pending comments, remain inactive normally, and only trigger when an administrator opens the review page. This kind of ambush-style attack specifically targets users with administrative privileges.
Among the three vulnerabilities reported by Anthropic, one was found in the WXR exporter. Attackers first store malicious input there without triggering it immediately. Only when a user exports content and the system re-picks up this old input to include in a database query does the vulnerability become active—a delayed-trigger backdoor. The other two were a denial-of-service vulnerability in the WP_Http::make_absolute_url() method and an access control issue allowing author role users to set posts as sticky. The former could cause the service to crash under specific requests, and the latter allowed regular authors who shouldn't have sticky permissions to manipulate the schedule.
Join Now