Your message dated Fri, 07 Aug 2026 08:22:53 +0000
with message-id <[email protected]>
and subject line Bug#1143843: fixed in wordpress 7.0.3+dfsg1-1
has caused the Debian Bug report #1143843,
regarding wordpress: CVE-2026-64638
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143843: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143843
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: wordpress
Version: 7.0.2+dfsg1-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for wordpress.

CVE-2026-64638[0]:
| Pre-auth reflected XSS on login screen with potential to lead to PHP
| code execution

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-64638
    https://www.cve.org/CVERecord?id=CVE-2026-64638
[1] 
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 7.0.3+dfsg1-1
Done: Craig Small <[email protected]>

We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated wordpress package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 07 Aug 2026 18:01:56 +1000
Source: wordpress
Architecture: source
Version: 7.0.3+dfsg1-1
Distribution: unstable
Urgency: high
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1143843
Changes:
 wordpress (7.0.3+dfsg1-1) unstable; urgency=high
 .
   * New upstream security release
     CVE-2026-64638 fix XSS in login that leads to RCE Closes: #1143843
Checksums-Sha1:
 6c8b4c9433e111e73d4f0247c32e3a5aad4cf9eb 2422 wordpress_7.0.3+dfsg1-1.dsc
 b380c06b526e40d9b8cb4b5dd44bffb0d1b2fe21 24072096 
wordpress_7.0.3+dfsg1.orig.tar.xz
 3ad5d5cac076d26080c2bef455b673cd262fd9bd 6893592 
wordpress_7.0.3+dfsg1-1.debian.tar.xz
 60dcbecd41de9988347a06c84bc02371e04584ad 7652 
wordpress_7.0.3+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
 4b7ad907e0f01b514d6f8ed5e2456c2cab1933b20e3e7faa9ea88a23b1e659d5 2422 
wordpress_7.0.3+dfsg1-1.dsc
 bca22633a05e80bfa71afe2da0b33220889eadac2076efbe16c465f7f6994acd 24072096 
wordpress_7.0.3+dfsg1.orig.tar.xz
 02f3935c30dd674cd5e0593f9ea5321b65d8268b3f47ff3ef6574aa90931910b 6893592 
wordpress_7.0.3+dfsg1-1.debian.tar.xz
 b7bf84a1053c6bac4c321f0dbd5b564d3d48366d1baf56e3aca3a6629483f646 7652 
wordpress_7.0.3+dfsg1-1_amd64.buildinfo
Files:
 1439c4e54656c7c363c14ffa6a6446d0 2422 web optional wordpress_7.0.3+dfsg1-1.dsc
 4b42718f50cd5d452ef4fbbb2565e005 24072096 web optional 
wordpress_7.0.3+dfsg1.orig.tar.xz
 075e419ef82497068338d7b82fdfcfde 6893592 web optional 
wordpress_7.0.3+dfsg1-1.debian.tar.xz
 03408dffb408e1f5fd6dee5702cac9f3 7652 web optional 
wordpress_7.0.3+dfsg1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmp1kWEACgkQAiFmwP88
hOOeBg/+LaW1QwREsW0rGSLCXOvZaobvS/mSnRicw+nqJiwohCsAxhfFhqDpsmY8
yYan84NTJy/95dXR5YRRVKmpGaYjOtdEVurI7Hh5aVMBVZUhBbUNb8q1LG3DRlGN
fmucZ7OACbNBveCwFu+cZL3oN+IzAN5V/3DmE2vfWZmHPmj6ityDgf7PmLDwWt5d
cYqXcsQ46/o8xoCEEx2gviqeHZ3fpKeW4EQkHnd6eBcCKSgO1tqP/2CCbFfWQkyp
Te5juYAzeMSCgEw0CN6IJsnKSTSrR1RSdsS0LM1Orljkz846RJF1IClUkrF4AYe2
xSEtIqs+X/zbVu0JqU96doV+G7t3fOsMZdebp69kekEDLfNwQUJB1w+ic2F/ZChZ
gmAEf9X/m/tMZ6aWZW43zz75eSKKKzi7SqyHod8+8XqUVT6UY/llwGxaH/AssNIz
7juzp6gPU1ZWWx/YtUpRBP/ZTgjTPZV5lO3SV57Pec9j9sYoN+dngFjkY6IJ4m8b
ox0liBPhSz6zIxisTuygviCvYKEOkoFZhfxX2d4UIbjSZdcSPjACaqcbub/TITXD
u0k85J21Jx7BtSdsfnPX8jXyeA7zF8xYje7+nlQ/wobW7XrpqSdjw9UpB3kQgQpY
haqrBC6swNrPfTG32yS/udVDmqHuuKzFH3Mv7JjI8ABFMz2FoW8=
=8v1y
-----END PGP SIGNATURE-----

Attachment: pgpgzj_Ra_t22.pgp
Description: PGP signature


--- End Message ---

Reply via email to