WordPress patches flaws in version 7.1.1
CERT-FR advisory warns of multiple WordPress vulnerabilities before 7.1.1 enabling data exposure, XSS, and security bypass.
CERT-FR published an advisory covering multiple vulnerabilities in WordPress affecting versions prior to 7.1.1. The flaws could allow an attacker to compromise data confidentiality, perform indirect remote code injection (cross-site scripting), and bypass security policy protections. No specific exploitation details, proof-of-concept code, or CVE identifiers were included in the advisory text.
There is no indication in the bulletin that these vulnerabilities are being exploited in the wild. WordPress addressed the issues in its 7.1.1 maintenance and security release, published on 17 September 2026. Defenders running WordPress installations should update to version 7.1.1 or later as the primary mitigation, per the vendor's security bulletin.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1200
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free