Hi Craig, On Tue, Jul 21, 2026 at 12:54:41PM +1000, Craig Small wrote: > Package: wordpress > Version: 7.0+dfsg1-1 > Severity: grave > Tags: security > Justification: user security hole > X-Debbugs-Cc: Debian Security Team <[email protected]> > > WordPress versions 6.9 and higher are vulnerable to a REST API batch-route > confusion weakness, which combined with an SQL injection issue > (GHSA-fpp7-x2x2-2mjf) leads to Remote Code Execution. > WordPress versions 7.0.2, 6.9.5, and 7.1 beta2 have been released, containing > fixes for the vulnerability. > > References: > > https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q > https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
This one claims the issue affects only 6.9 onwards but I see the mention of the REST API as well in https://github.com/WordPress/wordpress-develop/commit/c62f8c47314727184124b1227a00ee2eef546231 . Are the affected ranges correct or can you point where the issue got actually introdduced (for both CVEs) so we might update correctly the security-tracker metadata? Regards, Salvatore

