Hello, Bug #1148368 in wordpress reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/wordpress/-/commit/9ed24329ff93dc02ff664a0e821f15845dfea84e ------------------------------------------------------------------------ 7.1.1 New upstream security release Closes: #1148368 Fixes: CVE-2026-93485 and Click2Shell Stored XSS in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval). CVE-2026-93485 API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences. Stored XSS in some themes that support custom headers. Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org. (Click2Shell) Site Administrator can network-activate an installed Network-only plugin. Authenticated Path Traversal in WP REST Templates Controller. XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css. Contributor+ Arbitrary Post Overwrite. Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title. Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+. Comments, including notes, can be reparented by any authenticated user. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148368
Hello, Bug #1148368 in wordpress reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/wordpress/-/commit/e55cf5844b7c752d76550f2d22ed33fe2cf1df1b ------------------------------------------------------------------------ Upstream security release 6.8.9 * 6.8.8 backport of security release 7.0.4 Fixes: CVE-2026-65640 Closes: #1144955 * 6.8.9 backport of security release 7.1.1 Closes: #1148368 Stored XSS in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval). CVE-2026-93485 API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences. Stored XSS in some themes that support custom headers. Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org. (Click2Shell) Site Administrator can network-activate an installed Network-only plugin. Authenticated Path Traversal in WP REST Templates Controller. XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css. Contributor+ Arbitrary Post Overwrite. Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title. Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+. Comments, including notes, can be reparented by any authenticated user. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148368
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148368@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 21:21:36 +1000
Source: wordpress
Architecture: source
Version: 7.1.1+dfsg1-1
Distribution: unstable
Urgency: high
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1148368
Changes:
wordpress (7.1.1+dfsg1-1) unstable; urgency=high
.
* New upstream security release Closes: #1148368
Stored XSS in wpautop() allows an unauthenticated visitor to inject
script (subject to comment approval). CVE-2026-93485
API: set_modifiable_text() allows breaking out of a comment via
abrupt-closing sequences.
Stored XSS in some themes that support custom headers.
Specially crafted URLs can automatically install and preview an
inactive theme from WordPress.org. (Click2Shell)
Site Administrator can network-activate an installed Network-only plugin.
Authenticated Path Traversal in WP REST Templates Controller.
XML-RPC can be used to publish customize_changeset posts that bypass
checks for edit_css.
Contributor+ Arbitrary Post Overwrite.
Missing read_post check in attachment_submitbox_metadata() leaks a
private parent-post title.
Missing Authorization leads to Draft/Pending Post Slug Disclosure by
Contributor+.
Comments, including notes, can be reparented by any authenticated user.
Checksums-Sha1:
7b439e90f62a7ef1138a98f3ae28c11917311919 2359 wordpress_7.1.1+dfsg1-1.dsc
5dd435f4236a7dd9355cfe9ad2b78c66e28101dc 28033048 wordpress_7.1.1+dfsg1.orig.tar.xz
b2465d8a34dd48788411fde20c6e7830eab6c59c 1603688 wordpress_7.1.1+dfsg1-1.debian.tar.xz
c39570c0cfbf417b35d742b8be0c489748c9b8ef 7229 wordpress_7.1.1+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
62f6274ec1013e82f1e0b9e9e319b12f00fd87e9154e47651b623e3f19dbd4d3 2359 wordpress_7.1.1+dfsg1-1.dsc
65b73fd0416a3d208705cc619b54050070775ef6fac9ff67eed49cd6cdb1b3f2 28033048 wordpress_7.1.1+dfsg1.orig.tar.xz
eeff5e978e54f083d7c5edd69b7cb88b845dd26fcc28b6508285614722424b93 1603688 wordpress_7.1.1+dfsg1-1.debian.tar.xz
364a0f75fb98a13b315ec9b5039a764f66ad13c559b15dd309b456c8e73f3dca 7229 wordpress_7.1.1+dfsg1-1_amd64.buildinfo
Files:
672d2b6e0afe5837f9e681b53025b28b 2359 web optional wordpress_7.1.1+dfsg1-1.dsc
4540177ea4d6fc11955eb4e481e091b0 28033048 web optional wordpress_7.1.1+dfsg1.orig.tar.xz
c99018ffbe7bf16c67bd5b1d8fa668a1 1603688 web optional wordpress_7.1.1+dfsg1-1.debian.tar.xz
5abe1d0c161c9f3fc37de7b9609da320 7229 web optional wordpress_7.1.1+dfsg1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmqxE6AACgkQAiFmwP88
hOOx0g//ToI8qpHOM0QrVuEkzq2ccKZIU8JNCaMVvbRomwbG/6xmWfiiZqlRzNth
rqBypAGehuxXxmckhrJklnuj/W3Trd3O79gy8HhUkxm75SxcwHdisVa3T4qtvMi5
npftj2u7nItM7uVHfnPYdmbT/jr7hBflssZ3Xp0yGr2DpFh2XjI4baMdcqnqklYi
k+en/pwvtyh3+yQmkGIJQ5GE2/sFZZVj5VVvYv+QGifLYCrec1ZUThyYgoIFzuRx
krpV4vZPoY9BRW4jjh5iu/RTXoFUzlKqPs4rKiE9SaAY76/qQ2V/t5u9S1DGaZYA
Q9M3Wl/eqEn2qv6jxeOWBdz3v/d21FeFDBqj88f7aUHhbrTfVjFwv5xl6VnB6rw1
ANbJrls5kxgyUTC6/v+B6xWP3gL/OwxWD3BhXKPpDIspv1kbJmsmo1bfpnVm4htm
xVLtinXe3mCj+ySZCga0Ia6M/wUsjvbuvumEM/047oHvCrmiaP/SMQ21ohSci43r
LNgR3gYxXG0o4Z0iVo/1Aaa1YW1lGWABdWxS0sDoiOb4farQVHtRdwGC4bKPCqgz
1vSCuPqZwDQGM78kpteDscT0vo4jFCL4hu0v54Dne4Uw96fqOIB7ajYIh3hOeJ9o
GRTyR/cR9B23wN4aOboNBxOFotlA0W2CPk3zdY+yi8aHWWX9ELg=
=w9Bm
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148368@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 20:30:44 +1000
Source: wordpress
Binary: wordpress wordpress-l10n wordpress-theme-twentytwentyfive wordpress-theme-twentytwentyfour wordpress-theme-twentytwentythree
Architecture: source all
Version: 6.8.10+dfsg1-0+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Description:
wordpress - weblog manager
wordpress-l10n - weblog manager - language files
wordpress-theme-twentytwentyfive - weblog manager - twentytwentyfive theme files
wordpress-theme-twentytwentyfour - weblog manager - twentytwentyfour theme files
wordpress-theme-twentytwentythree - weblog manager - twentytwentythree theme files
Closes: 114873 1144955 1148368
Changes:
wordpress (6.8.10+dfsg1-0+deb13u1) trixie-security; urgency=high
.
* Three security updates
* 6.8.10 backport of security release 7.1.2 Closes: #114873
CVE-2026-87902: Unauthenticated path traversal in page-template resolution
leading to conditional RCE.
* 6.8.9 backport of security release 7.1.1 Closes: #1148368
Stored XSS in wpautop() allows an unauthenticated visitor to inject
script (subject to comment approval). CVE-2026-93485
API: set_modifiable_text() allows breaking out of a comment via
abrupt-closing sequences.
Stored XSS in some themes that support custom headers.
Specially crafted URLs can automatically install and preview an
inactive theme from WordPress.org. (Click2Shell)
Site Administrator can network-activate an installed Network-only plugin.
Authenticated Path Traversal in WP REST Templates Controller.
XML-RPC can be used to publish customize_changeset posts that bypass
checks for edit_css.
Contributor+ Arbitrary Post Overwrite.
Missing read_post check in attachment_submitbox_metadata() leaks a
private parent-post title.
Missing Authorization leads to Draft/Pending Post Slug Disclosure by
Contributor+.
Comments, including notes, can be reparented by any authenticated user.
* 6.8.8 backport of security release 7.0.4
Fixes: CVE-2026-65640 Closes: #1144955
Checksums-Sha1:
ff31ae8fcf1ad3d5660fd4d140ef666af28b5db1 2461 wordpress_6.8.10+dfsg1-0+deb13u1.dsc
e858d5e845e5b08cbd24d7003bce2700bf81deee 22359396 wordpress_6.8.10+dfsg1.orig.tar.xz
9a08d602a23da77246eafb46f8368cd5a78ab9ea 6913692 wordpress_6.8.10+dfsg1-0+deb13u1.debian.tar.xz
1d41e422fe9cec26e2e9b58d6397466e3397636f 4369808 wordpress-l10n_6.8.10+dfsg1-0+deb13u1_all.deb
06dfb929593e7fbd6a41772c14319630006882d4 7905728 wordpress-theme-twentytwentyfive_6.8.10+dfsg1-0+deb13u1_all.deb
745dc79cb2ab6e002089783a48d97fd8fdc8f2a9 2917672 wordpress-theme-twentytwentyfour_6.8.10+dfsg1-0+deb13u1_all.deb
4e042e10eb207e4d331c2ee673b71956e4818b85 2113212 wordpress-theme-twentytwentythree_6.8.10+dfsg1-0+deb13u1_all.deb
c63de337409d4882f7527e2dc91b889232197a5c 8930704 wordpress_6.8.10+dfsg1-0+deb13u1_all.deb
75b97492508824883e553c5ff095fe11be4c9e37 7782 wordpress_6.8.10+dfsg1-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
65c0ee0a619be836dca57538b25f3a482f19560bdd9e7805f3b22fe4de984e3f 2461 wordpress_6.8.10+dfsg1-0+deb13u1.dsc
e28ac95cc7f732fe88157c050750625aefcb7cbf3f41557315054bc51513fdec 22359396 wordpress_6.8.10+dfsg1.orig.tar.xz
bb5b9e133487c9b9c085bd9b577865b771d5ad41fdd946831b68a440e13e4a22 6913692 wordpress_6.8.10+dfsg1-0+deb13u1.debian.tar.xz
90e6686e78d5f67d9bfec2a9aae252f8985e4d4f3c4a51e7ba2092e3aa5009be 4369808 wordpress-l10n_6.8.10+dfsg1-0+deb13u1_all.deb
018758b33769f7ac35f42985a30e12c373e6454539cbb3858e413a2bebdf05f4 7905728 wordpress-theme-twentytwentyfive_6.8.10+dfsg1-0+deb13u1_all.deb
60a83bb2530ef4b9d9978b4f93f7a5d97d60614e7da517a722467c8c55e32323 2917672 wordpress-theme-twentytwentyfour_6.8.10+dfsg1-0+deb13u1_all.deb
cc84b527514db927237c372897901592dadbb654af658e1c7d60d2db66f5a21c 2113212 wordpress-theme-twentytwentythree_6.8.10+dfsg1-0+deb13u1_all.deb
73a8161a802db8451a473e0d2c5d3a93c7fe1d9d82b35728b35ee5d69d8c08df 8930704 wordpress_6.8.10+dfsg1-0+deb13u1_all.deb
c19d10c40412d461b09ecf291de3f3fbdd1d404a5cad1a5d157503f5f4bdc010 7782 wordpress_6.8.10+dfsg1-0+deb13u1_amd64.buildinfo
Files:
a1a5078776209e001e7800958b558a15 2461 web optional wordpress_6.8.10+dfsg1-0+deb13u1.dsc
b00a1c38c481e1165fd9adb1e0ad40dd 22359396 web optional wordpress_6.8.10+dfsg1.orig.tar.xz
d33817dd78f2cbaa569ae6e354a8cf5a 6913692 web optional wordpress_6.8.10+dfsg1-0+deb13u1.debian.tar.xz
20708fe08ebcc39bb107729615dc89d3 4369808 localization optional wordpress-l10n_6.8.10+dfsg1-0+deb13u1_all.deb
fba3296252395529bc946fc7bba1adef 7905728 web optional wordpress-theme-twentytwentyfive_6.8.10+dfsg1-0+deb13u1_all.deb
4dc877405f3e255a02af6ce56903b279 2917672 web optional wordpress-theme-twentytwentyfour_6.8.10+dfsg1-0+deb13u1_all.deb
5cb1edec094313117b43a1d67b0321a0 2113212 web optional wordpress-theme-twentytwentythree_6.8.10+dfsg1-0+deb13u1_all.deb
d377858e4833a55dfb8c856a3771ae84 8930704 web optional wordpress_6.8.10+dfsg1-0+deb13u1_all.deb
5dbce50941bba7e2a0c369e255112127 7782 web optional wordpress_6.8.10+dfsg1-0+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmq6Gm4ACgkQAiFmwP88
hONvtQ//ecw3d4TrZiMT1sqRyZJLrMdj7V8KKbFXi2huPafw6iliLKGpkY/BpuCT
yn2nCmbagbHAfAxYUPm3ndLEFASlxjdc5NQ8jqf+fL+Yun8Fw1CXDuqiv3OFzByC
5inmHG4KOnRRlm38DInhhosdsml9CWGhtyPwVrh5o8sM8mr9V5S4rgsffgveFL5h
eSSNAOSloB5LHn7s75I0BM7OrI82nk8HI/Srso28egaxxi/Km3B2WJPsxlZnVVVF
knWYBLmKiksn8ua50PKd9vaipNymNTwNB3e68AgWMOpQLldpNMW5OMpe++wjWCVo
N42Z8GtDOQN2w5Z/fGvDaPcidFqoijixWC23tpwMQJ24onicdnG0YgBqGwTlZDGz
Uq06xWyRrBhBNxcsuiyUjjsbczD0L2FQPvZgrSgL3rt4vEoUxVakzgeQdx8tmvxf
u03h0YiobNsYvIowniYeT1Pewa4Cbc0bGJMirBtkvAhZbzh4AHHX24AW1oKNdhZA
sPAjhqlqoN3ZFN/dREghWsSbyxtvodgxM1tBXhh6qmIRuoFTnfd4U/HCVq3ZeTFO
AT2iV1iZvebzo+PsSYzQz2xC9WmCZYXfPb5f9YAFAc+DlVtts9gxgz4hrBTZIAdp
4J0FCW2l+ix0HjN2FamNeKs9VE0uxkV+ZDz1tOvNbfMVY9HjhPA=
=UlA6
-----END PGP SIGNATURE-----