WordPress 7.1.1 fixes 11 security issues. Update client sites now

  • publication date
    September 21, 2026
  • categories
    News. WordPress

WordPress 7.1.1 is out, and the core team is recommending you update immediately. It’s a security and maintenance release: 11 security fixes, 17 Core bug fixes, and 19 Block Editor bug fixes (per the official release notes). This is exactly the kind of release a managed WordPress maintenance plan exists to catch before a client even notices.

What was fixed

  • Stored XSS in `wpautop()` that let an unauthenticated visitor inject script, subject to comment approval
  • Specially crafted URLs could silently install and preview an inactive theme from WordPress.org — the first step of a full admin-click-to-remote-shell chain, since patched (more on that one below)
  • Authenticated path traversal in the WP REST Templates Controller
  • Contributor+ arbitrary post overwrite, and several other Contributor/Editor-level privilege issues
  • XML-RPC could be used to bypass `edit_css` checks

Two of the eleven were responsibly reported by Anthropic’s own security research — a reminder that WordPress’s disclosure pipeline reaches well beyond the traditional WP security community.

What agencies should do this week

  • Update every client site to 7.1.1, or confirm automatic background updates already applied it
  • If you manage sites on a delayed-update policy for stability reasons, this is a release worth making an exception for — it’s explicitly flagged as security, not routine maintenance
  • 7.1.1 is a short-cycle release; the next major version, 7.2, isn’t expected until December, so there’s no “wait for the next one” argument here

What this means for Codelibry clients

If you’re on one of our maintenance plans, this release is already handled — applied, verified, and logged as its own line item in your next monthly maintenance report, so you’ll see exactly what shipped and when it was applied to your site. Nothing to chase down on your end. If you’re not on a plan yet, this is a fair example of what one actually buys you: someone applying and checking releases like this the week they ship, not whenever there’s time to get to it.

Source: WordPress.org

Vitalii Omelchenko
Founder at Codelibry and WordPress enthusiast. Helping digital agencies to protect their margins and do better at website delivery. Need help with wordpress builds? Book a call using the Contact page
our Blog

Explore our Latest Insights

company icon
A WooCommerce plugin is being actively exploited right now. Check if your clients run it
News
September 21, 2026
company icon
Click2Shell: the WordPress attack chain that turned one admin click into a remote shell
News
September 21, 2026
company icon
White label development for small agencies
WordPress
September 8, 2026
whatsapp icon