[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-63030
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 22 08:30:36 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e609b699 by Salvatore Bonaccorso at 2026-07-22T09:30:05+02:00
Update status for CVE-2026-63030
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6512,11 +6512,15 @@ CVE-2026-7364 (IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security V
NOT-FOR-US: IBM
CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a R ...)
- wordpress 7.0.2+dfsg1-1 (bug #1142511)
+ [trixie] - wordpress <not-affected> (Vulnerable code introduced later)
+ [bookworm] - wordpress <not-affected> (Vulnerable code introduced later)
+ [bullseye] - wordpress <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
NOTE: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
NOTE: https://github.com/WordPress/wordpress-develop/commit/85015b84fbc52bf6151a691299896b8971772594 (7.0.2)
NOTE: https://github.com/WordPress/wordpress-develop/commit/c8bdf1fa12355f79db94054d307d0e3898b501c9 (7.0.2)
NOTE: https://github.com/WordPress/wordpress-develop/commit/6f2074dda61864a03f334d70414d1690ce7e5c79 (6.9.5)
+ NOTE: The error handling in the problematic function is different in 6.8 and below.
CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0 ...)
- wordpress 7.0.2+dfsg1-1 (bug #1142510)
NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e609b69941437aac1ba6742025c7f6dde3935863
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e609b69941437aac1ba6742025c7f6dde3935863
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/d4a828cb/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list