Hi Craig, On Tue, Jul 21, 2026 at 04:17:47PM +1000, Craig Small wrote: > On Tue, 21 Jul 2026 at 15:10, Salvatore Bonaccorso <[email protected]> > wrote: > > > This one claims the issue affects only 6.9 onwards but I see the > > mention of the REST API as well in > > > > https://github.com/WordPress/wordpress-develop/commit/c62f8c47314727184124b1227a00ee2eef546231 > > . > > > > Are the affected ranges correct or can you point where the issue got > > actually introdduced (for both CVEs) so we might update correctly the > > security-tracker metadata? > > > They seem to be pretty clear that 60137 affects 6.8, 6.9 and 7.0 but 63030 > affects 6.9 and 7.0 only
Right that is my reading of the advisories as well. > However I have compared the two patches for 6.8 and 6.9 and they backport > the same patchset. > The two are: > c62f8c47314727184124b1227a00ee2eef546231 and > 6f2074dda61864a03f334d70414d1690ce7e5c79 > > I've asked the WordPress security team, it could be they're fixing both the > same way but there is no (known) active path for 6.8 Ok thanks for having done so. Let's see what they respond. > Sid got its security update upload just now, working on Trixie now Thanks, already updated the tracker earlier today. Regards, Salvatore

