- Package:
- src:wordpress
- Source:
- src:wordpress
- Submitter:
- Craig Small
- Date:
- 2026-08-12 05:23:02 UTC
- Severity:
- normal
- Tags:
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. References: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143843@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 07 Aug 2026 18:01:56 +1000
Source: wordpress
Architecture: source
Version: 7.0.3+dfsg1-1
Distribution: unstable
Urgency: high
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1143843
Changes:
wordpress (7.0.3+dfsg1-1) unstable; urgency=high
.
* New upstream security release
CVE-2026-64638 fix XSS in login that leads to RCE Closes: #1143843
Checksums-Sha1:
6c8b4c9433e111e73d4f0247c32e3a5aad4cf9eb 2422 wordpress_7.0.3+dfsg1-1.dsc
b380c06b526e40d9b8cb4b5dd44bffb0d1b2fe21 24072096 wordpress_7.0.3+dfsg1.orig.tar.xz
3ad5d5cac076d26080c2bef455b673cd262fd9bd 6893592 wordpress_7.0.3+dfsg1-1.debian.tar.xz
60dcbecd41de9988347a06c84bc02371e04584ad 7652 wordpress_7.0.3+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
4b7ad907e0f01b514d6f8ed5e2456c2cab1933b20e3e7faa9ea88a23b1e659d5 2422 wordpress_7.0.3+dfsg1-1.dsc
bca22633a05e80bfa71afe2da0b33220889eadac2076efbe16c465f7f6994acd 24072096 wordpress_7.0.3+dfsg1.orig.tar.xz
02f3935c30dd674cd5e0593f9ea5321b65d8268b3f47ff3ef6574aa90931910b 6893592 wordpress_7.0.3+dfsg1-1.debian.tar.xz
b7bf84a1053c6bac4c321f0dbd5b564d3d48366d1baf56e3aca3a6629483f646 7652 wordpress_7.0.3+dfsg1-1_amd64.buildinfo
Files:
1439c4e54656c7c363c14ffa6a6446d0 2422 web optional wordpress_7.0.3+dfsg1-1.dsc
4b42718f50cd5d452ef4fbbb2565e005 24072096 web optional wordpress_7.0.3+dfsg1.orig.tar.xz
075e419ef82497068338d7b82fdfcfde 6893592 web optional wordpress_7.0.3+dfsg1-1.debian.tar.xz
03408dffb408e1f5fd6dee5702cac9f3 7652 web optional wordpress_7.0.3+dfsg1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmp1kWEACgkQAiFmwP88
hOOeBg/+LaW1QwREsW0rGSLCXOvZaobvS/mSnRicw+nqJiwohCsAxhfFhqDpsmY8
yYan84NTJy/95dXR5YRRVKmpGaYjOtdEVurI7Hh5aVMBVZUhBbUNb8q1LG3DRlGN
fmucZ7OACbNBveCwFu+cZL3oN+IzAN5V/3DmE2vfWZmHPmj6ityDgf7PmLDwWt5d
cYqXcsQ46/o8xoCEEx2gviqeHZ3fpKeW4EQkHnd6eBcCKSgO1tqP/2CCbFfWQkyp
Te5juYAzeMSCgEw0CN6IJsnKSTSrR1RSdsS0LM1Orljkz846RJF1IClUkrF4AYe2
xSEtIqs+X/zbVu0JqU96doV+G7t3fOsMZdebp69kekEDLfNwQUJB1w+ic2F/ZChZ
gmAEf9X/m/tMZ6aWZW43zz75eSKKKzi7SqyHod8+8XqUVT6UY/llwGxaH/AssNIz
7juzp6gPU1ZWWx/YtUpRBP/ZTgjTPZV5lO3SV57Pec9j9sYoN+dngFjkY6IJ4m8b
ox0liBPhSz6zIxisTuygviCvYKEOkoFZhfxX2d4UIbjSZdcSPjACaqcbub/TITXD
u0k85J21Jx7BtSdsfnPX8jXyeA7zF8xYje7+nlQ/wobW7XrpqSdjw9UpB3kQgQpY
haqrBC6swNrPfTG32yS/udVDmqHuuKzFH3Mv7JjI8ABFMz2FoW8=
=8v1y
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143843@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 07 Aug 2026 18:13:22 +1000
Source: wordpress
Architecture: source
Version: 6.8.7+dfsg1-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1143843
Changes:
wordpress (6.8.7+dfsg1-0+deb13u1) trixie-security; urgency=medium
.
* New upstream security release
CVE-2026-64638 fix XSS in login that leads to RCE Closes: #1143843
Checksums-Sha1:
7d0b5305822dcbb2d70bada5670393df1f0f9df6 2454 wordpress_6.8.7+dfsg1-0+deb13u1.dsc
9a9ff10b7bbeed51af3b08ca38579b16e42257d7 22354772 wordpress_6.8.7+dfsg1.orig.tar.xz
3b9b7dea75e89fd7b5cc5be044e1fb9a2f858219 6913152 wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
5194860793dddeb0c1565eee212939e3a17b92d6 7762 wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
b3b3b541910585e898f58ffbde1da3a09dc3e4f4524e9639a1ce8f7200cddb54 2454 wordpress_6.8.7+dfsg1-0+deb13u1.dsc
052ab5d006571e9998919ebaf956b80a3342e5184b5a44fee65588ca34e88c5f 22354772 wordpress_6.8.7+dfsg1.orig.tar.xz
3722f356d0d1cce6d42c9024d59779b7b771136ddef5aa4c2ec404f69990848f 6913152 wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
52ae28c0c154acb0e74113d83d450db05a41a7e08e4237b87ff1ddb4cfc16e22 7762 wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
Files:
d306ebfc5bc748c0fc880c41f12fdee4 2454 web optional wordpress_6.8.7+dfsg1-0+deb13u1.dsc
678d8aacc14065c7f8de0b741a72aad5 22354772 web optional wordpress_6.8.7+dfsg1.orig.tar.xz
e2c11d0330b7e5c8af6a74e77b7d6551 6913152 web optional wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
d29fed3905715cfa62d733464ffb312d 7762 web optional wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmp4Q+YACgkQAiFmwP88
hONIPA//X42EHssF0O7V05WSTUHZpfxwt6nKPSuegCxZ9Z00bQs+WC9g0d8ilR4v
qhN5a6xy7ETYojxxf3RlKi332MAG8xamozkmo8rcknfj0W1/Mwe81RKTQ5Q932Fi
mDklxLHVr7Noo2AAJvydCLrifGL/cacDlJjMF7+Gq5vUZKHgaN6pH3wCbpYCRZbF
Rq1p1JRYBHSz/vy1yTUADWFD0fvrQCosGfIaklXeAbucQisdcQSEymKFdX9feSa9
CNmwpxosPRq82xfnPoSoU/Ae2d5fLoDai+TgbVCqrfDOQWTaMS4vUsbkzZh2GeVh
EHdXxLLWi/TaEIk2OCpaplcIvmGHmUxAEScu7TCLZ2zkaNRDjwA9Mro+bVgbsp9q
F7w7n2+y+LQxpCvxIFp+RPTLo4kDW4Ti1kYXW5IMD3vK2vRR3gqyF8WxCcdF+Mze
NLK4O/umtk98CuOSmypF0b3t1613kBnUHfuhn+q4TCCQhg6dbYq2OYxPeLs3ADHN
7QqW9WF+buhBhPS3FlkSLYbXvFxwN4P6mEvcjwxk+BtS4Uoayfb3XcxFJQWXkHQr
4C6KEPCxEwAMm6Fj+8W05dzFO+bK7/E4Foc0HEDNMBCVW5HxIfkMnBMwzuiKJAlW
3c3wXDnCwhqrvXZ/gJuNQdMyHqBf2LH25NgzwOQiOYvCjJH0Vuw=
=6sVN
-----END PGP SIGNATURE-----