[Git][security-tracker-team/security-tracker][master] Add tracking of two wordpress issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 21 06:10:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1a672a77 by Salvatore Bonaccorso at 2026-07-21T07:07:46+02:00
Add tracking of two wordpress issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3065,9 +3065,19 @@ CVE-2026-7667 (IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated att
 CVE-2026-7364 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify ...)
 	NOT-FOR-US: IBM
 CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a R ...)
-	NOT-FOR-US: WordPress plugin
+	- wordpress <unfixed> (bug #1142511)
+	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
+	NOTE: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/85015b84fbc52bf6151a691299896b8971772594 (7.0.2)
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/c8bdf1fa12355f79db94054d307d0e3898b501c9 (7.0.2)
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79 (6.9.5)
 CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0 ...)
-	NOT-FOR-US: WordPress plugin
+	- wordpress <unfixed> (bug #1142510)
+	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
+	NOTE: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/74d37a344cbf28e9187a1a5ca71b33d186bcd333 (7.0.2)
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79 (6.9.5)
+	NOTE: https://github.com/WordPress/wordpress-develop/commit/c62f8c47314727184124b1227a00ee2eef546231 (6.8.6)
 CVE-2026-57980 (Authentication bypass using an alternate path or channel in Microsoft  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-56741 (JLine is a Java library for handling console input. Prior to 3.30.14,  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a672a7779e4451fdc96ff504ac96b49c69ae2e3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a672a7779e4451fdc96ff504ac96b49c69ae2e3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/97a9638d/attachment.htm>


More information about the debian-security-tracker-commits mailing list