Your message dated Tue, 21 Jul 2026 06:34:20 +0000
with message-id <[email protected]>
and subject line Bug#1142511: fixed in wordpress 7.0.2+dfsg1-1
has caused the Debian Bug report #1142511,
regarding CVE-2026-63030: REST API confusion and SQLi gives Remote Code 
Execution
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142511: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142511
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: wordpress
Version: 7.0+dfsg1-1
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>

WordPress versions 6.9 and higher are vulnerable to a REST API batch-route 
confusion weakness, which combined with an SQL injection issue 
(GHSA-fpp7-x2x2-2mjf) leads to Remote Code Execution.
WordPress versions 7.0.2, 6.9.5, and 7.1 beta2 have been released, containing 
fixes for the vulnerability.

References:
 
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
 https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

-- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
'stable-debug'), (500, 'stable'), (50, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.95+deb13-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_AU:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages wordpress depends on:
ii  apache2 [httpd]                         2.4.68-1~deb13u1
ii  ca-certificates                         20250419
pn  default-mysql-client | virtual-mysql-c  <none>
    lient
pn  libapache2-mod-php | php                <none>
pn  libjs-cropper                           <none>
ii  libjs-lodash                            4.17.21+dfsg+~cs8.31.198.20210220-9
ii  libjs-underscore                        1.13.4~dfsg+~1.11.4-3
pn  php-gd                                  <none>
pn  php-getid3                              <none>
pn  php-mysql | php-mysqlnd                 <none>

Versions of packages wordpress recommends:
pn  wordpress-l10n                    <none>
pn  wordpress-theme-twentytwentyfive  <none>

Versions of packages wordpress suggests:
pn  default-mysql-server | virtual-mysql-server  <none>
pn  php-curl                                     <none>
pn  php-imagick                                  <none>
pn  php-mbstring                                 <none>
pn  php-ssh2                                     <none>
ii  php-xml                                      2:8.4+96
pn  php-zip                                      <none>
ii  php8.4-xml [php-xml]                         8.4.23-1~deb13u1

--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 7.0.2+dfsg1-1
Done: Craig Small <[email protected]>

We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated wordpress package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 21 Jul 2026 16:05:26 +1000
Source: wordpress
Architecture: source
Version: 7.0.2+dfsg1-1
Distribution: unstable
Urgency: high
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1142510 1142511
Changes:
 wordpress (7.0.2+dfsg1-1) unstable; urgency=high
 .
   * New upstream security release
   * CVE-2026-63030 fix a REST API batch-route confusion Closes: #1142511
   * CVE-2026-60137 fix facilitated SQL injection Closes: #1142510
Checksums-Sha1:
 fab7c03091b0090dd9ab7acc9860cff1ec69f3bf 2422 wordpress_7.0.2+dfsg1-1.dsc
 18fbedb21b88cb4a749e163c6a7c5bca429ac5d1 24071936 
wordpress_7.0.2+dfsg1.orig.tar.xz
 678d52749a6a4238aa821eaf001060c9adc49ff8 6893532 
wordpress_7.0.2+dfsg1-1.debian.tar.xz
 b98a9b10b12316318736717ff5a98e3e35f623d4 7652 
wordpress_7.0.2+dfsg1-1_amd64.buildinfo
Checksums-Sha256:
 ffa2a1086c138819fa92a21098a5b2115879f359763f069f694d845aede083f4 2422 
wordpress_7.0.2+dfsg1-1.dsc
 ced42e107b33fc41ecd32f5e24d9151c8f45cb5b2f1b356662d044e75b96d6a4 24071936 
wordpress_7.0.2+dfsg1.orig.tar.xz
 b31480adc4cc8c03609fbac88efc98d26a0b60b0f00810df2d056923ee2042a9 6893532 
wordpress_7.0.2+dfsg1-1.debian.tar.xz
 d4869d1a24ae254f723bea3c01c6efc2b17c564df0b701f01b93adc9f0008f3c 7652 
wordpress_7.0.2+dfsg1-1_amd64.buildinfo
Files:
 6c7020f9223febeba5f91beb64938b81 2422 web optional wordpress_7.0.2+dfsg1-1.dsc
 75c6e954a6c37af74b90a1b2b44c5490 24071936 web optional 
wordpress_7.0.2+dfsg1.orig.tar.xz
 90d1f509e9fd2ce8123bbb265f1fc763 6893532 web optional 
wordpress_7.0.2+dfsg1-1.debian.tar.xz
 4b0c403bd268c534f38f322f6f94bcbf 7652 web optional 
wordpress_7.0.2+dfsg1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmpfDZYACgkQAiFmwP88
hOOJhQ/9G0DLsBmrbCalywA7BgQNbr853BtEBnI4WOzgLF02n4ACZXsuH+Rk1Sqg
JxJvacinVSRDS+qOqYYlD7FCtDkfPzkLBHdyttjekYh0+0KFuoUV9eC8eHFIylPC
1FbQ3kUfkCdRRhQj6Dc7z9y3W7SEZ4nkMVUaFNPTYpAGb0odejcoHC8OL3sbD0yZ
5DyGn+Kp6PJScS6LMEI6OR5KFicfAtHKdQM2fhRjrv2N7nYxR6STQQPf/60YIFpo
5wF8WmMDREQbrtRow6P10uuJG0M71IqDUzpDt2CN/I1ry/EGZ2hYEfh9J1HRSSBN
SP8jvOeQGMhnGfkOJzhIdcDt/qkwSQ7B+z/JSQknu4mO2ahhgWbGrwTXCO2V8aNa
wekKkTX8kBidh5Oi+6vM2yuQyvY5EQLw5KuNj3psyC+Feveya6xjhDnVBwXPVich
wBroqZKjAd3+WqZTDgdNBVjDYtJL3oXHv8GFtsLhcswZWUrCnIE/+yqJM2o5qyk1
rPbfc5Zx2eYbiDXWOJsVFSMsyHcKWINK4JVIirQtoVSK4/wVOhscusRb0s9lf5YA
PtEZ8YsqyAV0y9MQksHS18+OQcdGxK1v9uN+TRolOivvd7sI9v6aqTOIf95wze0d
2NN8wodkrRFgSywLK3UFpNVLFijajZpno5ltlC3/hNRn7SMF+zg=
=rEkP
-----END PGP SIGNATURE-----

Attachment: pgpQb_hggED38.pgp
Description: PGP signature


--- End Message ---

Reply via email to