WordPress versions 6.8 and higher are vulnerable to an SQL injection issue. In WordPress versions 6.9 and higher, this combined with a REST API batch-route confusion issue (GHSA-ff9f-jf42-662q) leads to Remote Code Execution. WordPress versions 7.0.2, 6.9.5, 6.8.6, and 7.1 beta2 have been released, containing fixes for the vulnerability. References: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Hello, Bug #1142510 in wordpress reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/wordpress/-/commit/a101ab6594387105cfd258b29a3ed4667852353e ------------------------------------------------------------------------ New upstream security release 7.0.2 CVE-2026-63030 fix a REST API batch-route confusion Closes: #1142511 CVE-2026-60137 fix facilitated SQL injection Closes: #1142510 Updated block.min.js patch as usual ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1142510
We believe that the bug you reported is fixed in the latest version of wordpress, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1142510@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Craig Small <csmall@debian.org> (supplier of updated wordpress package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 21 Jul 2026 16:05:26 +1000 Source: wordpress Architecture: source Version: 7.0.2+dfsg1-1 Distribution: unstable Urgency: high Maintainer: Craig Small <csmall@debian.org> Changed-By: Craig Small <csmall@debian.org> Closes: 1142510 1142511 Changes: wordpress (7.0.2+dfsg1-1) unstable; urgency=high . * New upstream security release * CVE-2026-63030 fix a REST API batch-route confusion Closes: #1142511 * CVE-2026-60137 fix facilitated SQL injection Closes: #1142510 Checksums-Sha1: fab7c03091b0090dd9ab7acc9860cff1ec69f3bf 2422 wordpress_7.0.2+dfsg1-1.dsc 18fbedb21b88cb4a749e163c6a7c5bca429ac5d1 24071936 wordpress_7.0.2+dfsg1.orig.tar.xz 678d52749a6a4238aa821eaf001060c9adc49ff8 6893532 wordpress_7.0.2+dfsg1-1.debian.tar.xz b98a9b10b12316318736717ff5a98e3e35f623d4 7652 wordpress_7.0.2+dfsg1-1_amd64.buildinfo Checksums-Sha256: ffa2a1086c138819fa92a21098a5b2115879f359763f069f694d845aede083f4 2422 wordpress_7.0.2+dfsg1-1.dsc ced42e107b33fc41ecd32f5e24d9151c8f45cb5b2f1b356662d044e75b96d6a4 24071936 wordpress_7.0.2+dfsg1.orig.tar.xz b31480adc4cc8c03609fbac88efc98d26a0b60b0f00810df2d056923ee2042a9 6893532 wordpress_7.0.2+dfsg1-1.debian.tar.xz d4869d1a24ae254f723bea3c01c6efc2b17c564df0b701f01b93adc9f0008f3c 7652 wordpress_7.0.2+dfsg1-1_amd64.buildinfo Files: 6c7020f9223febeba5f91beb64938b81 2422 web optional wordpress_7.0.2+dfsg1-1.dsc 75c6e954a6c37af74b90a1b2b44c5490 24071936 web optional wordpress_7.0.2+dfsg1.orig.tar.xz 90d1f509e9fd2ce8123bbb265f1fc763 6893532 web optional wordpress_7.0.2+dfsg1-1.debian.tar.xz 4b0c403bd268c534f38f322f6f94bcbf 7652 web optional wordpress_7.0.2+dfsg1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmpfDZYACgkQAiFmwP88 hOOJhQ/9G0DLsBmrbCalywA7BgQNbr853BtEBnI4WOzgLF02n4ACZXsuH+Rk1Sqg JxJvacinVSRDS+qOqYYlD7FCtDkfPzkLBHdyttjekYh0+0KFuoUV9eC8eHFIylPC 1FbQ3kUfkCdRRhQj6Dc7z9y3W7SEZ4nkMVUaFNPTYpAGb0odejcoHC8OL3sbD0yZ 5DyGn+Kp6PJScS6LMEI6OR5KFicfAtHKdQM2fhRjrv2N7nYxR6STQQPf/60YIFpo 5wF8WmMDREQbrtRow6P10uuJG0M71IqDUzpDt2CN/I1ry/EGZ2hYEfh9J1HRSSBN SP8jvOeQGMhnGfkOJzhIdcDt/qkwSQ7B+z/JSQknu4mO2ahhgWbGrwTXCO2V8aNa wekKkTX8kBidh5Oi+6vM2yuQyvY5EQLw5KuNj3psyC+Feveya6xjhDnVBwXPVich wBroqZKjAd3+WqZTDgdNBVjDYtJL3oXHv8GFtsLhcswZWUrCnIE/+yqJM2o5qyk1 rPbfc5Zx2eYbiDXWOJsVFSMsyHcKWINK4JVIirQtoVSK4/wVOhscusRb0s9lf5YA PtEZ8YsqyAV0y9MQksHS18+OQcdGxK1v9uN+TRolOivvd7sI9v6aqTOIf95wze0d 2NN8wodkrRFgSywLK3UFpNVLFijajZpno5ltlC3/hNRn7SMF+zg= =rEkP -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142510@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 21 Jul 2026 16:46:23 +1000
Source: wordpress
Architecture: source
Version: 6.8.6+dfsg1-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1142510
Changes:
wordpress (6.8.6+dfsg1-0+deb13u1) trixie-security; urgency=medium
.
* New upstream security release 6.8.6
* CVE-2026-60137 fix facilitated SQL injection Closes: #1142510
* Includes release 6.8.4 and 6.8.5 updates
- Check permissions on edit notes CVE-2026-3906 (not vulnerable)
Checksums-Sha1:
86ad2320a06f96f2c0208ec1dd30fd9a1d230f40 2454 wordpress_6.8.6+dfsg1-0+deb13u1.dsc
801ef7748ced4da04f426f5dceef72371c07051b 22353380 wordpress_6.8.6+dfsg1.orig.tar.xz
b8f881557349979d02732fd7d23a8466a01ec264 6913388 wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
1f92ee113f746ef19ce01e297c44c5f2764e61aa 7762 wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
751c842edf129ba381c37e43b395ae1c7dbeff98fb0091316ee2943ad819ebeb 2454 wordpress_6.8.6+dfsg1-0+deb13u1.dsc
c1673d6833400e9c7bd76f95de5046bc7e5cdc523eafff219ba100761542c624 22353380 wordpress_6.8.6+dfsg1.orig.tar.xz
a82e4d7c0fe6b7b7687bf70125792b515947ce765f8c04bd7f430c31a0188a18 6913388 wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
46a57b4288f3c1d435d4f359e0ea9175a2b5b41329244faf8e4215197d65964d 7762 wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo
Files:
a2d21c07d60039cd8e78b91fec910c11 2454 web optional wordpress_6.8.6+dfsg1-0+deb13u1.dsc
69173a72348b2ed003958b78846cce3f 22353380 web optional wordpress_6.8.6+dfsg1.orig.tar.xz
9999da2d469430a32399b3ae707d0d63 6913388 web optional wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
0c13b6a677fe0edae5a38f73c1cb0a44 7762 web optional wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmpiDzEACgkQAiFmwP88
hONiJw/+PHxii5BRvgiZLAlWTtbTP0TtSuRQq6XAPoo50Xq2Th6mfs6QCRL58W2v
AwKz1Ws5xe4wC7G+zeDFQ1DldW++yZyxi6FQpCtEa2p9teaWSBBGPbse7PtylxGV
pxiew5ZbgiYarL0rqKvw9Kt+4+W9VR9VsmYF21LFn3TKDDgPfWp7fAji//ccMK9D
3fS3KMNC85Anl64hB6H41SezwVSYLY4QnSZ6Bh22O0L8ghjsvdSdjJFBPGULL2m7
VvQcamxvPkwaJeLZCnco4EOQrHTaA89TGLvA3jzXWoHT7vNavuRV1pP3flZTGXQI
bgmHYNZYaQevlJqQQwZ3AHL+bzNpFBSC6c/oAochV06zRPYxW8vUYcJN8nyDDRrR
zCEi58JNwuYeEhAsTtrnv7Io8hk1TRk1zXm/DRCt7jYf0iRAhsuRFofL12yiFBmI
6FLKIq8kJA3ZPXZQEDk/8ZA7mQdH56Z8NBKSz2j0l5bWqHliRIyEy6sRfHNOrnzJ
KS6i8dF2TuqXDvkt/1YuFAsBOumaBR+p5PpZYdn4b6LX/aKhjuYbctTrOoAnD9Qy
o7VVwfvMSVi8UOvtL6FgpOGOtYVDb1Ne0TgwbUogozQ3RJCxn2V0E6rcKLQTP7vA
SMUSJjAjtwr5YdftuPVqeIiv/5k3egfL8HpEfBCzEzyZCSV69LU=
=fJng
-----END PGP SIGNATURE-----