What changed: WordPress 7.1.3 fixes 7 security issues and 4 bugs, including a stored XSS on the Comments admin page, a DoS issue in WP_Http::make_absolute_url(), a second-order SQL injection in WXR export, a weakness letting Author-role users sticky posts, unauthenticated disclosure of comments on private/unpublished posts, XSS via Imgur embeds, and forgeable parameters on the {status}_{type} hook; the update is available via WordPress.org download or via the Dashboard's Updates screen.
Who is affected
The source does not specify a particular business type; it affects all sites running WordPress and the people operating them.
What it means for your business
For businesses running WordPress, this means sites need the 7.1.3 update applied immediately to close 7 security vulnerabilities, including stored XSS, SQL injection, and a DoS issue.
What to do
Update your site now: click 'Updates' then 'Update Now' in the WordPress Dashboard, or let automatic background updates complete the install.
When it takes effect
The source gives no separate effective date; as this is a security release, immediate update is recommended.
Source: https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/