Your message dated Wed, 12 Aug 2026 05:21:05 +0000
with message-id <[email protected]>
and subject line Bug#1143843: fixed in wordpress 6.8.7+dfsg1-0+deb13u1
has caused the Debian Bug report #1143843,
regarding wordpress: CVE-2026-64638 pre-auth reflected XSS on login screen
leads to RCE
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143843: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143843
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: wordpress
Version: 7.0.2+dfsg1-1
Severity: grave
Tags: security
Justification: user security hole
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login
screen.
Via a specially crafted malicious third-party website hosted by an attacker, it
is possible for this to be escalated to an RCE vulnerability with conditions
outside of the attackers control. This requires successful social engineering
of and explicit interaction by the target victim.
This issue affects all versions of WordPress.
References:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
-- System Information:
Debian Release: 13.6
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
'stable-debug'), (500, 'stable'), (50, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 6.12.100+deb13-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8),
LANGUAGE=en_AU:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages wordpress depends on:
ii apache2 [httpd] 2.4.68-1~deb13u1
ii ca-certificates 20250419
pn default-mysql-client | virtual-mysql-c <none>
lient
pn libapache2-mod-php | php <none>
pn libjs-cropper <none>
ii libjs-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9
ii libjs-underscore 1.13.4~dfsg+~1.11.4-3
pn php-gd <none>
pn php-getid3 <none>
pn php-mysql | php-mysqlnd <none>
Versions of packages wordpress recommends:
pn wordpress-l10n <none>
pn wordpress-theme-twentytwentyfive <none>
Versions of packages wordpress suggests:
pn default-mysql-server | virtual-mysql-server <none>
pn php-curl <none>
pn php-imagick <none>
pn php-mbstring <none>
pn php-ssh2 <none>
ii php-xml 2:8.4+96
pn php-zip <none>
ii php8.4-xml [php-xml] 8.4.24-1~deb13u1
--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 6.8.7+dfsg1-0+deb13u1
Done: Craig Small <[email protected]>
We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated wordpress package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 07 Aug 2026 18:13:22 +1000
Source: wordpress
Architecture: source
Version: 6.8.7+dfsg1-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1143843
Changes:
wordpress (6.8.7+dfsg1-0+deb13u1) trixie-security; urgency=medium
.
* New upstream security release
CVE-2026-64638 fix XSS in login that leads to RCE Closes: #1143843
Checksums-Sha1:
7d0b5305822dcbb2d70bada5670393df1f0f9df6 2454
wordpress_6.8.7+dfsg1-0+deb13u1.dsc
9a9ff10b7bbeed51af3b08ca38579b16e42257d7 22354772
wordpress_6.8.7+dfsg1.orig.tar.xz
3b9b7dea75e89fd7b5cc5be044e1fb9a2f858219 6913152
wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
5194860793dddeb0c1565eee212939e3a17b92d6 7762
wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
b3b3b541910585e898f58ffbde1da3a09dc3e4f4524e9639a1ce8f7200cddb54 2454
wordpress_6.8.7+dfsg1-0+deb13u1.dsc
052ab5d006571e9998919ebaf956b80a3342e5184b5a44fee65588ca34e88c5f 22354772
wordpress_6.8.7+dfsg1.orig.tar.xz
3722f356d0d1cce6d42c9024d59779b7b771136ddef5aa4c2ec404f69990848f 6913152
wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
52ae28c0c154acb0e74113d83d450db05a41a7e08e4237b87ff1ddb4cfc16e22 7762
wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
Files:
d306ebfc5bc748c0fc880c41f12fdee4 2454 web optional
wordpress_6.8.7+dfsg1-0+deb13u1.dsc
678d8aacc14065c7f8de0b741a72aad5 22354772 web optional
wordpress_6.8.7+dfsg1.orig.tar.xz
e2c11d0330b7e5c8af6a74e77b7d6551 6913152 web optional
wordpress_6.8.7+dfsg1-0+deb13u1.debian.tar.xz
d29fed3905715cfa62d733464ffb312d 7762 web optional
wordpress_6.8.7+dfsg1-0+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmp4Q+YACgkQAiFmwP88
hONIPA//X42EHssF0O7V05WSTUHZpfxwt6nKPSuegCxZ9Z00bQs+WC9g0d8ilR4v
qhN5a6xy7ETYojxxf3RlKi332MAG8xamozkmo8rcknfj0W1/Mwe81RKTQ5Q932Fi
mDklxLHVr7Noo2AAJvydCLrifGL/cacDlJjMF7+Gq5vUZKHgaN6pH3wCbpYCRZbF
Rq1p1JRYBHSz/vy1yTUADWFD0fvrQCosGfIaklXeAbucQisdcQSEymKFdX9feSa9
CNmwpxosPRq82xfnPoSoU/Ae2d5fLoDai+TgbVCqrfDOQWTaMS4vUsbkzZh2GeVh
EHdXxLLWi/TaEIk2OCpaplcIvmGHmUxAEScu7TCLZ2zkaNRDjwA9Mro+bVgbsp9q
F7w7n2+y+LQxpCvxIFp+RPTLo4kDW4Ti1kYXW5IMD3vK2vRR3gqyF8WxCcdF+Mze
NLK4O/umtk98CuOSmypF0b3t1613kBnUHfuhn+q4TCCQhg6dbYq2OYxPeLs3ADHN
7QqW9WF+buhBhPS3FlkSLYbXvFxwN4P6mEvcjwxk+BtS4Uoayfb3XcxFJQWXkHQr
4C6KEPCxEwAMm6Fj+8W05dzFO+bK7/E4Foc0HEDNMBCVW5HxIfkMnBMwzuiKJAlW
3c3wXDnCwhqrvXZ/gJuNQdMyHqBf2LH25NgzwOQiOYvCjJH0Vuw=
=6sVN
-----END PGP SIGNATURE-----
pgp8YJ4UbJ78u.pgp
Description: PGP signature
--- End Message ---