WordPress 7.1.1 security alert: 11 flaws you must fix now
WordPress released version 7.1.1 on September 17, 2026 — a security and maintenance update that fixes 11 security issues (plus 17 core bug fixes and 19 Block Editor fixes). The security team recommends updating immediately.
If your company runs a WordPress site —or your provider does— this is the security alert of the week.
The trickiest flaw: a link that installs a theme
Among the 11 fixes there is a particularly uncomfortable one: a specially crafted URL can automatically install and preview an inactive theme from WordPress.org. No server access is needed: it is enough for an administrator with an active session to open that link (for example, from an email or a message). From there, the attacker can chain steps toward code execution.
This is the pattern behind today’s attacks: they don’t break the door — they convince you to open the link.
The other 10 security fixes
- Stored XSS in
wpautop()that an unauthenticated visitor can inject (subject to comment approval). - Stored XSS in some themes that support custom headers.
- The HTML API allowed breaking out of a comment with abrupt-closing sequences.
- Authenticated path traversal in the REST templates controller.
- XML-RPC could publish changes bypassing
edit_csschecks. - A Contributor+ could overwrite arbitrary posts.
- Private post title leaked due to a missing
read_postcheck. - Draft/pending post slug disclosure due to missing authorization.
- Any authenticated user could reparent comments.
- A Site Administrator could network-activate an installed network-only plugin.
What it means for a small business in Panama
WordPress powers most small-business websites in Panama: fast, affordable and flexible… and also a favorite target for attackers, precisely because it is everywhere. The good news: this one is solved with a simple action.
- Update now: Dashboard → Updates → update to 7.1.1 (or keep automatic security updates enabled).
- Review plugins and themes: outdated ones are the most common way in.
- Backups and monitoring: a recent backup turns a disaster into a bad afternoon.
The real risk isn’t “getting hacked because you’re famous”: it’s leaving the door open through neglect. An outdated site is an invitation.
How we can help
At PG Tech we handle your website maintenance and security: up-to-date updates, WordPress hardening, verified backups and monitoring. We also provide IT support for your whole operation.
Frequently Asked Questions
Does my site run WordPress, and should I update?
Yes. If you run WordPress 7.1 or earlier, update to 7.1.1: it fixes 11 security issues. Automatic security updates usually apply it on their own; it’s worth verifying.
What happens if I don’t update?
You remain exposed to the fixed flaws, including the one that lets a theme be installed with a click from a link. Attackers scan outdated sites automatically.
Can updating break my site?
This is a maintenance release (7.1.1), not a major jump: the risk is low. Still, keep a backup and do it during low-traffic hours.
Source: official WordPress team announcement, “WordPress 7.1.1 Maintenance and Security Release” (wordpress.org/news, September 17, 2026).
