Hi Craig,

On Tue, Jul 21, 2026 at 04:17:47PM +1000, Craig Small wrote:
> On Tue, 21 Jul 2026 at 15:10, Salvatore Bonaccorso <[email protected]>
> wrote:
> 
> > This one claims the issue affects only 6.9 onwards but I see the
> > mention of the REST API as well in
> >
> > https://github.com/WordPress/wordpress-develop/commit/c62f8c47314727184124b1227a00ee2eef546231
> > .
> >
> > Are the affected ranges correct or can you point where the issue got
> > actually introdduced (for both CVEs) so we might update correctly the
> > security-tracker metadata?
> >
> They seem to be pretty clear that 60137 affects 6.8, 6.9 and 7.0  but 63030
> affects 6.9 and 7.0 only

Right that is my reading of the advisories as well.

> However I have compared the two patches for 6.8 and 6.9 and they backport
> the same patchset.
> The two are:
> c62f8c47314727184124b1227a00ee2eef546231 and
> 6f2074dda61864a03f334d70414d1690ce7e5c79
> 
> I've asked the WordPress security team, it could be they're fixing both the
> same way but there is no (known) active path for 6.8

Ok thanks for having done so. Let's see what they respond.

> Sid got its security update upload just now, working on Trixie now

Thanks, already updated the tracker earlier today.

Regards,
Salvatore

Reply via email to