Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN913
_____________________________________________________________________

DATE                : 18/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running WordPress versions prior to
                                           7.1.1.
  
=====================================================================
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
_____________________________________________________________________

WordPress 7.1.1 Maintenance and Security Release

This security and maintenance release features 17 bug fixes on Core,
19 bug fixes for the Block Editor, and 11 security fixes.

Because this is a security release, it is recommended that you update
your sites immediately.

You can download WordPress 7.1.1 from WordPress.org, or visit your
WordPress Dashboard, click “Updates”, and then click “Update Now”.
If you have sites that support automatic background updates, the
update process will begin automatically.

WordPress 7.1.1 is a short-cycle release. The next major release
will be version 7.2 and is currently planned for December.

For more information, please visit the WordPress 7.1.1 HelpHub site.
Security updates included in this release

The security team would like to thank the following people for
responsibly reporting vulnerabilities, and allowing them to be
fixed in this release:

    Stored cross-site scripting in wpautop() allows an
unauthenticated visitor to inject script (subject to comment
approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
    HTML API: set_modifiable_text() allows breaking out of a
comment via abrupt-closing sequences, reported by Jeremy Felt
of the WordPress Security Team.

    Stored XSS in some themes that support custom headers,
reported by Jeremy Felt of the WordPress Security Team.
    Specially crafted URLs can automatically install and
preview an inactive theme from WordPress.org, reported by
Paulos Yibelo and pwn.ai.

    Site Administrator can network-activate an installed
Network-only plugin, reported by Jesse McNeil.

    Authenticated Path Traversal in WP REST Templates
Controller, reported by Anthropic.

    XML-RPC can be used to publish customize_changeset
posts that bypass checks for edit_css, reported by Ben
Bidner of the WordPress Security Team.

    Contributor+ Arbitrary Post Overwrite, reported by
Anthropic.

    Missing read_post check in attachment_submitbox_metadata()
leaks a private parent-post title, reported by HDWSec.
    Missing Authorization leads to Draft/Pending Post Slug
Disclosure by Contributor+, reported by Jakub Herman.
    Comments, including notes, can be reparented by any
authenticated user, reported by Justin Hart, Viridis Security.


Thank you to these WordPress contributors

This release was led by Adam Silverstein, Adrian Duffell,
Andrei Draganescu, and Aaron Jorbin.

WordPress 7.1.1 would not have been possible without the
contributions of the following people. Their asynchronous
coordination to deliver maintenance and security fixes into
a stable release is a testament to the power and capability
of the WordPress community.

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




