This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes.
Because this is a security release, it is recommended that you update your sites immediately.
You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.
WordPress 7.1.1 is a short-cycle release. The next major release will be version 7.2 and is currently planned for December.
For more information, please visit the WordPress 7.1.1 HelpHub site.
Security updates included in this release
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- Stored cross-site scripting in
wpautop()allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.). - HTML API:
set_modifiable_text()allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team. - Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish
customize_changesetposts that bypass checks foredit_css, reported by Ben Bidner of the WordPress Security Team. - Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing
read_postcheck inattachment_submitbox_metadata()leaks a private parent-post title, reported by HDWSec. - Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
Thank you to these WordPress contributors
This release was led by Adam Silverstein, Adrian Duffell, Andrei Draganescu, and Aaron Jorbin.
WordPress 7.1.1 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver maintenance and security fixes into a stable release is a testament to the power and capability of the WordPress community.
Aaron Jorbin, abrahamfariaz, Adam Silverstein, Adi Moldovan, Aki Hamano, Alex Concha, andreasca, Andrei Draganescu, Andrew Duthie, Andrew Serong, André Maneiro, annezazu, Anthony White, Arkaprabha Chowdhury, Azragh, Barry, buffer1024, Chunhui Ouyang, Courtney Robertson, Dagan, Daniel Richards, Daniel Rodriguez, David Biňovec, Deepak Kumar, Dennis Snell, DevSaiful, Dhruvang21, Dominik Schilling, Ehtisham Siddiqui, Ella Van Durpe, Erick Wambua, FahimMurshed, Fernando Tellado, fiocavallari, George Mamadashvili, George Vasiliades, gregbenz, Harish Tewari, Hit Bhalodia, Isabel Brison, Jake Spurlock, Jb Audras, Jeffrey Paul, Jeremy Felt, Jiwoon Kim, Joe Dolson, Joe Hoyle, Joe McGill, Joen Asmussen, Johannes Jülg, John Blackbourn, Jon Surrell, Jonathan Desrosiers, Josh, Kamran Abdul Aziz, Khokan Sardar, Kira Schroder, kleisauke, Kushagra Goyal, l1onofjudah, Lance Willett, luksusspokoju, Manzoor Wani, Marco Ciampini, marcs0h, Marin Atanasov, Michael, Mohammad Jangda, mrkenobi, Mukesh Panchal, Nawazkhan Pathan, Nik Tsekouras, Parth Jogi, Pascal Birchler, Paul Biron, Paul Kevan, Peter Wilson, Rafie Muhammad, ramonopoly, Rashed Hossain, Ressl, Riad Benguella, Rudy Faile, Sainath Poojary, Scott Kingsley Clark, Sergey Biryukov, Shail Mehta, Shameem – a11n, siliconforks, Slava Abakumov, Sukhendu Sekhar Guria, Utsav Ladani, vortfu, Weston Ruter, wolf45 plus representatives from Automattic, Bluehost, GoDaddy, Pantheon, and WP Engine.
Backports
As a courtesy, the security fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.
How to contribute
To get involved in WordPress core development, head over to Trac, pick a ticket, and join the conversation in the #core channel. Need help? Check out the Core Contributor Handbook.
Props to Ehtisham Siddiqui, Lance Willett, Weston Ruter, and Adam Silverstein for proofreading.

