# WordPress 7.1.1 security alert: 11 flaws you must fix now

> WordPress 7.1.1 fixes 11 security issues, including a URL that installs a theme with one click. What to do and how to protect your site in Panama.

URL: https://pgtechcorp.com/en/wordpress-7-1-1-security-alert-update-now/
Actualizado: 2026-09-18

---

WordPress released version **7.1.1** on September 17, 2026 — a **security and maintenance** update that fixes **11 security issues** (plus 17 core bug fixes and 19 Block Editor fixes). The security team recommends updating **immediately**.

If your company runs a WordPress site —or your provider does— this is the security alert of the week.

## The trickiest flaw: a link that installs a theme

Among the 11 fixes there is a particularly uncomfortable one: a **specially crafted URL can automatically install and preview an inactive theme from WordPress.org**. No server access is needed: it is enough for an administrator with an active session to open that link (for example, from an email or a message). From there, the attacker can chain steps toward code execution.

This is the pattern behind today’s attacks: they don’t break the door — they convince you to open the link.

## The other 10 security fixes

- Stored XSS in `wpautop()` that an unauthenticated visitor can inject (subject to comment approval).

- Stored XSS in some themes that support custom headers.

- The HTML API allowed breaking out of a comment with abrupt-closing sequences.

- Authenticated path traversal in the REST templates controller.

- XML-RPC could publish changes bypassing `edit_css` checks.

- A Contributor+ could overwrite arbitrary posts.

- Private post title leaked due to a missing `read_post` check.

- Draft/pending post slug disclosure due to missing authorization.

- Any authenticated user could reparent comments.

- A Site Administrator could network-activate an installed network-only plugin.

## What it means for a small business in Panama

WordPress powers most small-business websites in Panama: fast, affordable and flexible… and also a favorite target for attackers, precisely because it is everywhere. The good news: this one is solved with a simple action.

- **Update now:** Dashboard → Updates → update to 7.1.1 (or keep automatic security updates enabled).

- **Review plugins and themes:** outdated ones are the most common way in.

- **Backups and monitoring:** a recent backup turns a disaster into a bad afternoon.

The real risk isn’t “getting hacked because you’re famous”: it’s leaving the door open through neglect. An outdated site is an invitation.

## How we can help

At PG Tech we handle your [website maintenance and security](/en/services/cybersecurity/): up-to-date updates, WordPress hardening, verified backups and monitoring. We also provide [IT support](/en/services/it-support/) for your whole operation.

[Get a free website check](https://wa.me/50769606453)

## Frequently Asked Questions

### Does my site run WordPress, and should I update?

Yes. If you run WordPress 7.1 or earlier, update to 7.1.1: it fixes 11 security issues. Automatic security updates usually apply it on their own; it’s worth verifying.

### What happens if I don’t update?

You remain exposed to the fixed flaws, including the one that lets a theme be installed with a click from a link. Attackers scan outdated sites automatically.

### Can updating break my site?

This is a maintenance release (7.1.1), not a major jump: the risk is low. Still, keep a backup and do it during low-traffic hours.

*Source: official WordPress team announcement, “WordPress 7.1.1 Maintenance and Security Release” (wordpress.org/news, September 17, 2026).*

---

PG Tech Corporation, Inc. — Obarrio, Ave. Samuel Lewis, PH Marfil, Ciudad de Panama, Panama
Contacto: WhatsApp 6960-6453 · https://pgtechcorp.com
