Hi Craig,
The following vulnerability was published for wordpress, filling at RC
level but maybe it can be downgraded. The new 7.1.3 releases fixes
CVE-2026-66666[0]:
| Insertion of Sensitive Information Into Sent Data vulnerability in
| Automattic WordPress allows Retrieve Embedded Sensitive Data. This
| issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through
| 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7
| through 6.7.9, and from 6.6 through 6.6.9.
and a couple of other issues (with no known CVE yet):
from [1].
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-66666
https://www.cve.org/CVERecord?id=CVE-2026-66666
[1] https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore