There are 7 security fixes and 4 bug fixes. Because it is a security release it is recommended to update sites immediately.

WordPress 7.1.3 Another Security Release
Jake Spurlock @ wordpress.org • 9 hours ago

Jake Spurlock @ wordpress.org • 9 hours ago
There are 7 security fixes and 4 bug fixes. Because it is a security release it is recommended to update sites immediately.

Robert Abela @ melapress.com • 3 weeks ago
Some things that jumped out at me were that a large number of site owners don’t have a response plan and 17% discover a security problem because a notice on a search engine.

David Perex @ make.wordpress.org • 4 weeks ago
An update on automatic security reviews for plugins on the WP plugin directory.

Rae Morey @ therepository.email • 1 month ago
The WordPress security team received 773 reports of security vulnerabilities in August, up from around 20-30 a month last year. The team starts to put some new limitations on what they will accepts via the HackerOne disclosure program.

Istvan Marton @ wordfence.com • 1 month ago
If I was reading this correctly, the payload is planted using a ping-back. I wonder how many of these types of holes there are?

Scott Kingsley Clark @ pods.io • 1 month ago
It looks like more vulnerabilities were found after the team patched Pods earlier in the mont

Konstantin Ryabitsev @ people.kernel.org • 1 month ago
Konstantin Ryabitsev from the Linux Kernel team reports on their fight with AI bots. The current situation doesn’t seem sustainable.

Roger Montti @ searchenginejournal.com • 1 month ago
Surprisingly there is nothing on the plugin page on WP org about Rank Math creating unauthorized admin access. I would expect that Rank Math would be suspended, at least until fixed, if not for longer. Roger Montti’s report helps to get the word out about this bad behavior.

Elijah Mills @ breakdance.combreak • 1 month ago
These are both security releases to patch access control issues in the Design Library endpoints which were reachable without authentication.