[Git][security-tracker-team/security-tracker][master] Add CVE-2026-65640/wordpress

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 22:02:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
609ed8ad by Salvatore Bonaccorso at 2026-08-19T23:02:22+02:00
Add CVE-2026-65640/wordpress

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4106,7 +4106,9 @@ CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to continuou
 CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
 	NOT-FOR-US: ERPNext
 CVE-2026-65640 (WordPress is vulnerable to a remote code execution vulnerability via m ...)
-	TODO: check
+	- wordpress <unfixed>
+	NOTE: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
+	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
 CVE-2026-65351 (This issue was addressed through improved state management. This issue ...)
 	NOT-FOR-US: Apple
 CVE-2026-65349 (An out-of-bounds read was addressed with improved input validation. Th ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/609ed8adc852dfbb75325a8e19b7c8c4375ebf25

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/609ed8adc852dfbb75325a8e19b7c8c4375ebf25
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/ce1b306b/attachment.htm>


More information about the debian-security-tracker-commits mailing list