---
title: "WordPress 7.1.1 And 7.1.2 Security Releases: What Was Patched And How To Harden Your Site With Nexter Extension"
url: https://nexterwp.com/blog/wordpress-7-1-2-security-update/
date: 2026-10-01
modified: 2026-10-01
lang: en
author: "Aditya Sharma"
description: "WordPress 7.1.1 and 7.1.2 fixed 12 security issues. See what was patched, which version to run, and how Nexter Extension helps harden your site."
image: https://nexterwp.com/wp-content/uploads/2026/10/wordpress-7-1-2-security-update-featured-1024x538.jpg
word_count: 1997
---

# WordPress 7.1.1 And 7.1.2 Security Releases: What Was Patched And How To Harden Your Site With Nexter Extension

 

WordPress shipped two security releases five days apart. [WordPress 7.1.1](https://wordpress.org/documentation/wordpress-version/version-7-1-1/) landed on September 17, 2026 with 11 security fixes, and [WordPress 7.1.2](https://wordpress.org/documentation/wordpress-version/version-7-1-2/) followed on September 22 with one more: an unauthenticated path traversal in page-template resolution that the release notes say could lead to conditional remote code execution.

If you run a WordPress 7.1 site, the action is simple: be on 7.1.2. The harder question is what else to do while you are in there, and how much of that a plugin can honestly help with. I checked both against the official release pages and against the Nexter Extension settings on a test site.

This post lists what was patched, which version each supported branch should be on, how to update without a surprise, and where Nexter Extension helps and where it does not. Nexter Extension cannot patch WordPress core. Only the core update does that.

Table of Contents

## What WordPress 7.1.1 And 7.1.2 Fixed

The 7.1.1 release notes describe a security and maintenance release with 17 bug fixes in core, 21 bug fixes for the block editor and 11 security fixes. The release candidate announcement is [here](https://make.wordpress.org/core/2026/09/10/wordpress-7-1-1-rc1-is-now-available/) if you want the bug fix list. The security items are below, using the wording from the official notes.

| Release | What the release notes describe | Who can trigger it, per the notes |
| ------- | ------------------------------- | --------------------------------- |
| 7.1.1 | A crafted URL could install and preview a theme from WordPress.org | Not stated |
| 7.1.1 | Stored cross-site scripting (XSS) in custom header images on some themes | Not stated |
| 7.1.1 | Information disclosure exposing the title of a private parent post | Not stated |
| 7.1.1 | HTML API issue where modified text could break out of an HTML comment | Not stated |
| 7.1.1 | A site administrator on multisite could network-activate a network-only plugin | Site administrator |
| 7.1.1 | Arbitrary post overwrite | Contributor and above |
| 7.1.1 | Path traversal in the REST API templates controller | Authenticated user |
| 7.1.1 | Any authenticated user could reparent comments, including notes | Any authenticated user |
| 7.1.1 | XML-RPC issue letting changeset posts bypass the custom CSS capability check | Not stated |
| 7.1.1 | Disclosure of draft and pending post slugs | Contributor and above |
| 7.1.1 | Stored XSS via paragraph formatting, subject to comment approval | Unauthenticated |
| 7.1.2 | Path traversal in page-template resolution leading to conditional remote code execution | Unauthenticated |
Source: the official WordPress 7.1.1 and 7.1.2 release pages on wordpress.org, read on October 1, 2026. I have shortened the wording. The last column repeats what the notes state and says Not stated where they do not.

Read the last column before you decide how urgent this is. Several of these need a logged-in account, which matters for sites with open registration or many contributors. The 7.1.2 issue is the opposite: the notes call it unauthenticated, so no account is needed.

I am deliberately not going further than the notes. I have not reproduced any of these and I will not describe how they work. The point of this post is the response, not the exploit.

## Which Version Should You Be On Right Now?

WordPress says only the most recent version is actively supported, and that it back-ported these fixes as a courtesy. The 7.1.2 page lists the patched release for each older branch. These are the ones most sites are still on:

| If you run | Update to | Source |
| ---------- | --------- | ------ |
| WordPress 7.1 | 7.1.2 | 7.1.2 release page |
| WordPress 7.0 | 7.0.6 | 7.1.2 release page |
| WordPress 6.9 | 6.9.9 | 7.1.2 release page |
| WordPress 6.8 | 6.8.10 | 7.1.2 release page |
| WordPress 6.7 | 6.7.9 | 7.1.2 release page |
Patched releases for the 7.1.2 fix, from the official release page. The 7.1.1 fixes were back-ported separately as 7.0.5, 6.9.8 and 6.8.9, so landing on the latest number in your branch covers both.

If you are on a branch older than these, the notes list a patched version for it too, but you should plan a move to a supported branch. [My WordPress 7.1 breakdown](https://nexterwp.com/blog/wordpress-7-1/) covers what the current branch changed, and the [WordPress 7.2 roadmap](https://nexterwp.com/blog/wordpress-7-2/) covers the next one.

## How To Update Without Breaking The Site

I opened the Updates screen on a test site that was still on WordPress 7.1. WordPress offered 7.1.2 straight away and printed its usual warning to back up the database and files first.

![WordPress Updates screen showing an update from WordPress 7.1 to 7.1.2 and a note that automatic update is overdue](https://nexterwp.com/wp-content/uploads/2026/10/wordpress-7-1-2-update-core-screen.webp)The WordPress Updates screen on a test site still on 7.1, with 7.1.2 offered and automatic updates overdue by three weeks.

Notice the line above the update button: automatic update overdue by three weeks, with a hint that WP-Cron may have a problem. That is a test site where nothing triggers cron, so it is an exaggerated case. It is still a useful reminder that automatic updates depend on WordPress being able to run its scheduled tasks.

This is the order I would follow on a real site:

- Take a full backup of the database and files, and confirm you can restore it.

- Open Dashboard, then Updates, and update WordPress core to the latest number in your branch.

- Update plugins and themes next. On my test site, Nexter Blocks and Nexter Extension both listed compatibility with 7.1.2 as Yes.

- Load the front end, the login page and one editor screen. Check your error log rather than trusting a blank page.

- If you manage many sites, stage one first and roll out the rest once it is clean.

## What To Check If A Core Update Gives You A 500 Error

Not every update goes cleanly. In the r/Wordpress thread about 7.1.1, one commenter reported a 500 error after updating from 7.1.0 and said reverting fixed it. I have no way to verify an individual report, so treat it as a signal that you should keep a backup, not as a known bug.

Another commenter in the same thread suggested checking two things before blaming the release: whether PHP-FPM is still serving cached files from opcache, and whether a plugin calls a function that moved. Restarting PHP-FPM and reading the actual error log line is cheap and rules both out. That is community advice, not official guidance.

This is where a Nexter Extension utility helps. The Utilities screen includes a WP Debug Mode toggle, which I can see in the screenshot below, and a Rollback Manager. Be clear about the limit: Rollback Manager rolls back plugins and themes from WordPress.org. It does not roll back WordPress core.

![Nexter Extension Utilities screen with the Rollback Manager toggle](https://nexterwp.com/wp-content/uploads/2026/10/nexter-extension-rollback-manager-utilities.webp)Rollback Manager sits on the Utilities screen of Nexter Extension. It rolls back plugins and themes, not WordPress core.

The plugin's own code backs that up. For themes that do not come from WordPress.org it shows a message that no rollback is available. So if a plugin update after the core update causes the 500, you can step that one plugin back. If core is the problem, you restore from your backup.

## A Quick Triage: How Exposed Are You?

Everyone should update. But the table above suggests a quick way to judge how much the 7.1.1 list should worry you, based on how your site is set up.

- **Open registration or many contributors.** You are the most exposed to the issues that need a logged-in account, such as Contributor level post overwrite, draft slug disclosure and comment reparenting. Patch first, then review accounts.

- **Multisite.** One item is specific to a site administrator network-activating a network-only plugin. If you give site administrators to people you do not fully trust, that one is yours.

- **Apps that use XML-RPC.** Some mobile apps and older publishing tools still use it. Check before you switch it off, because disabling it will stop them working.

- **A single-author site with no registration.** The authenticated items matter less to you. The 7.1.2 issue is unauthenticated, so you still need that update.

None of this changes the advice to update. It only tells you where to spend the next hour after you have.

## What Nexter Extension Can And Cannot Do Here

I opened the Security screen in [Nexter Extension](https://nexterwp.com/nexter-extension/). My test site runs version 4.7.8, while the WordPress.org listing shows 4.7.10 today, so your screen may differ slightly from my screenshots.

![Nexter Extension Security screen listing Advanced Security, CAPTCHA, Custom Login URL, SVG Upload, 2-Factor Authentication, Content Protection, Login Email Notification and Limit Login Attempts](https://nexterwp.com/wp-content/uploads/2026/10/nexter-extension-security-settings-panel.webp)The Security screen in Nexter Extension. Advanced Security, CAPTCHA, Custom Login URL and Limit Login Attempts are available without Pro on my test install.

On that screen, Advanced Security, CAPTCHA, Custom Login URL, SVG Upload and Limit Login Attempts have working toggles. 2-Factor Authentication, Content Protection and Login Email Notification carry a Pro badge and a lock on my install. The Limit Login Attempts card is labelled Freemium.

### Advanced Security Options

![Nexter Extension Advanced Security options including Disable XML-RPC, Hide WordPress Version, Disable File Editor, REST API and iFrame Security](https://nexterwp.com/wp-content/uploads/2026/10/nexter-extension-advanced-security-options.webp)Advanced Security in Nexter Extension: Disable XML-RPC, Hide WordPress Version, Disable File Editor, Secure Cookies and more.

Advanced Security opens a panel of switches: Disable XML-RPC, Hide WordPress Version, Remove REST API Links, Disable File Editor, Remove Meta Generator, XSS Protection, a REST API dropdown, an iFrame Security dropdown, Secure Cookies, Last Login Date and Time, and Registration Date and Time. Hide Email from Spam Bots, Hide Telephone Secure Spam Bots and Hide Author URLs for Security carry Pro badges.

Here is how I would map those to the problems in this release, without overclaiming:

| Problem in the release notes | Nexter Extension option | Honest effect |
| ---------------------------- | ----------------------- | ------------- |
| XML-RPC changeset custom CSS bypass | Disable XML-RPC | Removes the XML-RPC entry point, so that route is closed. The core update is still what fixes the bug. |
| Issues that need a logged-in account | Limit Login Attempts, CAPTCHA, Custom Login URL | Makes account takeover by guessing harder. Does not fix the bug. |
| Unauthenticated path traversal (7.1.2) | None | Nothing here mitigates it. Update core. |
| Impact if an admin account is taken over | Disable File Editor | Removes the built-in theme and plugin file editor as a place to run code. |
| Version fingerprinting | Hide WordPress Version, Remove Meta Generator | Hides the version from the page source. It is not a security fix. |
My reading of the release notes against the Nexter Extension options on version 4.7.8. These reduce exposure. None of them replaces updating WordPress.

### Limit Login Attempts

![Nexter Extension Limit Login Attempts settings showing 5 failed attempts before a 15 minute lockout](https://nexterwp.com/wp-content/uploads/2026/10/nexter-extension-limit-login-attempts-settings.webp)Limit Login Attempts defaults on my test install: 5 failed attempts before a 15-minute lockout, then 30 minutes after repeated lockouts.

The defaults on my install were five failed attempts before a 15-minute lockout, then a 30-minute block after repeated lockouts. There is also a field to detect the visitor IP from a specific header, which matters behind a proxy or CDN, and a View Logs button. I wrote up the full setup, including login alerts, in [Nexter Extension login security](https://nexterwp.com/blog/nexter-extension-login-attempt-monitoring/).

Several of the 7.1.1 issues need Contributor access or any logged-in account. That makes account hygiene part of the response. Review who has an account and what role it has, and [the guide to WordPress user roles](https://nexterwp.com/blog/wordpress-user-roles/) explains what each level can do.

## A Hardening Setup I Would Use After Updating

This is a short list, in priority order, that you can do in about fifteen minutes once core is on the patched version:

- Confirm WordPress is on the latest number in your branch and that automatic minor updates are actually running.

- Turn on Limit Login Attempts and check the IP header setting if you sit behind a CDN.

- Turn on Disable File Editor and, if nothing on your site uses it, Disable XML-RPC.

- Remove or downgrade accounts that no longer need Contributor access or above.

- Add CAPTCHA to the login and registration forms if you allow open registration.

- Keep one tested backup you have actually restored.

None of that is a substitute for a full security review. [How to secure a WordPress website: the 2026 hardening checklist](https://nexterwp.com/blog/ultimate-wordpress-security-guide/) goes much further, and if you are weighing dedicated tools, [the best WordPress security plugins](https://nexterwp.com/blog/best-wordpress-security-plugins/) compares them.

If you want the 2-Factor Authentication or Login Email Notification options, those were Pro on my install. The [free versus Pro page](https://nexterwp.com/free-vs-pro/) lists what each tier includes.

## What This Doesn't Cover

- I did not reproduce or test any of the vulnerabilities. I am relying on the official release notes for their descriptions.

- I did not test whether Disable XML-RPC or any other option blocks a specific exploit. I describe what the option does, not a guarantee.

- I could not verify the individual reports in the r/Wordpress thread.

- My screenshots are from Nexter Extension 4.7.8. The listing shows 4.7.10, so labels and defaults may have changed.

- I did not cover hosting-level protection such as a web application firewall.

- This is not a replacement for patching. Update WordPress first.

## Suggested Reading

- [How to Secure a WordPress Website: The 2026 Hardening Checklist](https://nexterwp.com/blog/ultimate-wordpress-security-guide/)

- [Nexter Extension Login Security: Setting Up Limit Login Attempts and Login Alerts](https://nexterwp.com/blog/nexter-extension-login-attempt-monitoring/)

- [Best WordPress Security Plugins](https://nexterwp.com/blog/best-wordpress-security-plugins/)

- [WordPress User Roles Explained](https://nexterwp.com/blog/wordpress-user-roles/)

- [WordPress 7.1: What’s New and What Got Deferred](https://nexterwp.com/blog/wordpress-7-1/)

[Explore Nexter Extension](https://nexterwp.com/nexter-extension/)

#### Stay updated with Helpful WordPress Tips, Insider Insights, and Exclusive Updates – Subscribe now to keep up with Everything Happening on WordPress!

Subscribe