Hi Craig,

On Tue, Jul 21, 2026 at 12:54:41PM +1000, Craig Small wrote:
> Package: wordpress
> Version: 7.0+dfsg1-1
> Severity: grave
> Tags: security
> Justification: user security hole
> X-Debbugs-Cc: Debian Security Team <[email protected]>
> 
> WordPress versions 6.9 and higher are vulnerable to a REST API batch-route 
> confusion weakness, which combined with an SQL injection issue 
> (GHSA-fpp7-x2x2-2mjf) leads to Remote Code Execution.
> WordPress versions 7.0.2, 6.9.5, and 7.1 beta2 have been released, containing 
> fixes for the vulnerability.
> 
> References:
>  
> https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
>  https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

This one claims the issue affects only 6.9 onwards but I see the
mention of the REST API as well in
https://github.com/WordPress/wordpress-develop/commit/c62f8c47314727184124b1227a00ee2eef546231
.

Are the affected ranges correct or can you point where the issue got
actually introdduced (for both CVEs) so we might update correctly the
security-tracker metadata?

Regards,
Salvatore

Reply via email to