WordPress 7.1.1 security alert: 11 flaws you must fix now

WordPress released version 7.1.1 on September 17, 2026 — a security and maintenance update that fixes 11 security issues (plus 17 core bug fixes and 19 Block Editor fixes). The security team recommends updating immediately.

If your company runs a WordPress site —or your provider does— this is the security alert of the week.

The trickiest flaw: a link that installs a theme

Among the 11 fixes there is a particularly uncomfortable one: a specially crafted URL can automatically install and preview an inactive theme from WordPress.org. No server access is needed: it is enough for an administrator with an active session to open that link (for example, from an email or a message). From there, the attacker can chain steps toward code execution.

This is the pattern behind today’s attacks: they don’t break the door — they convince you to open the link.

The other 10 security fixes

  • Stored XSS in wpautop() that an unauthenticated visitor can inject (subject to comment approval).
  • Stored XSS in some themes that support custom headers.
  • The HTML API allowed breaking out of a comment with abrupt-closing sequences.
  • Authenticated path traversal in the REST templates controller.
  • XML-RPC could publish changes bypassing edit_css checks.
  • A Contributor+ could overwrite arbitrary posts.
  • Private post title leaked due to a missing read_post check.
  • Draft/pending post slug disclosure due to missing authorization.
  • Any authenticated user could reparent comments.
  • A Site Administrator could network-activate an installed network-only plugin.

What it means for a small business in Panama

WordPress powers most small-business websites in Panama: fast, affordable and flexible… and also a favorite target for attackers, precisely because it is everywhere. The good news: this one is solved with a simple action.

  • Update now: Dashboard → Updates → update to 7.1.1 (or keep automatic security updates enabled).
  • Review plugins and themes: outdated ones are the most common way in.
  • Backups and monitoring: a recent backup turns a disaster into a bad afternoon.

The real risk isn’t “getting hacked because you’re famous”: it’s leaving the door open through neglect. An outdated site is an invitation.

How we can help

At PG Tech we handle your website maintenance and security: up-to-date updates, WordPress hardening, verified backups and monitoring. We also provide IT support for your whole operation.

Get a free website check

Frequently Asked Questions

Does my site run WordPress, and should I update?

Yes. If you run WordPress 7.1 or earlier, update to 7.1.1: it fixes 11 security issues. Automatic security updates usually apply it on their own; it’s worth verifying.

What happens if I don’t update?

You remain exposed to the fixed flaws, including the one that lets a theme be installed with a click from a link. Attackers scan outdated sites automatically.

Can updating break my site?

This is a maintenance release (7.1.1), not a major jump: the risk is low. Still, keep a backup and do it during low-traffic hours.

Source: official WordPress team announcement, “WordPress 7.1.1 Maintenance and Security Release” (wordpress.org/news, September 17, 2026).

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *