WordPress Ships a Security Fix for Eleven Flaws

WordPress released version 7.1.1 on 17 September, a security update patching eleven separate flaws in the software that runs a large share of the UK's small business websites. WordPress's own release announcement lists eleven separate fixes: stored cross-site scripting bugs, a path traversal issue, and several ways a lower-permission account could be made to act like a higher one. Its own advice is blunt. Update now.
Whether that has already happened depends on how your site is set up. WordPress can install a security release like this one automatically in the background, and most hosts and agencies leave that switched on by default. Where it is not, though, or where a plugin or a cautious host has turned it off, the fix just sits there in the WordPress Dashboard's Updates screen until somebody clicks it.
If you or whoever built your site can log into WordPress, that screen is worth two minutes. It names the version currently running and offers 7.1.1 if it has not already arrived on its own. If nobody has logged in for months, that is worth noticing on its own account, not just because of this release.
None of the eleven fixes needed a login to exploit outright. Several do give an existing lower-level account, a contributor, say, more reach than it should have: overwriting someone else's draft, seeing a private post's title, installing a theme through a specially crafted link. For any site with more than one person able to log in, that is the detail worth reading past the headline for.
Whoever is responsible for keeping a site patched is worth pinning down before it matters, not after, which is the same starting point as this guide on keeping a small site secure. Every site we build runs on the £69 a month care plan, which covers exactly this kind of update alongside hosting and backups, so a release like this one is not something you need to notice at all. See what that looks like if patch days are not how you want to spend an afternoon.