#1150336 wordpress: CVE-2026-66666 and other issues fixed with 7.1.3 maintenance release

Package:
src:wordpress
Source:
src:wordpress
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 18:55:03 UTC
Severity:
normal
Tags:
#1150336#5
Date:
2026-10-08 18:52:48 UTC
From:
To:
Hi Craig,

The following vulnerability was published for wordpress, filling at RC
level but maybe it can be downgraded. The new 7.1.3 releases fixes

CVE-2026-66666[0]:
| Insertion of Sensitive Information Into Sent Data vulnerability in
| Automattic WordPress allows Retrieve Embedded Sensitive Data.  This
| issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through
| 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7
| through 6.7.9, and from 6.6 through 6.6.9.

and a couple of other issues (with no known CVE yet):

from [1].



If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66666
https://www.cve.org/CVERecord?id=CVE-2026-66666
[1] https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore