Your message dated Fri, 24 Jul 2026 09:17:06 +0000
with message-id <[email protected]>
and subject line Bug#1142510: fixed in wordpress 6.8.6+dfsg1-0+deb13u1
has caused the Debian Bug report #1142510,
regarding CVE-2026-60137: SQL injection in WP_Query gives RCE
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142510: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142510
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: wordpress
Version: 7.0+dfsg1-1
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>

WordPress versions 6.8 and higher are vulnerable to an SQL injection issue.

In WordPress versions 6.9 and higher, this combined with a REST API batch-route 
confusion issue (GHSA-ff9f-jf42-662q) leads to Remote Code Execution.

WordPress versions 7.0.2, 6.9.5, 6.8.6, and 7.1 beta2 have been released, 
containing fixes for the vulnerability.

References:
 
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
 https://wordpress.org/news/2026/07/wordpress-7-0-2-release/




-- System Information:
Debian Release: 13.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
'stable-debug'), (500, 'stable'), (50, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.95+deb13-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_AU:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages wordpress depends on:
ii  apache2 [httpd]                         2.4.68-1~deb13u1
ii  ca-certificates                         20250419
pn  default-mysql-client | virtual-mysql-c  <none>
    lient
pn  libapache2-mod-php | php                <none>
pn  libjs-cropper                           <none>
ii  libjs-lodash                            4.17.21+dfsg+~cs8.31.198.20210220-9
ii  libjs-underscore                        1.13.4~dfsg+~1.11.4-3
pn  php-gd                                  <none>
pn  php-getid3                              <none>
pn  php-mysql | php-mysqlnd                 <none>

Versions of packages wordpress recommends:
pn  wordpress-l10n                    <none>
pn  wordpress-theme-twentytwentyfive  <none>

Versions of packages wordpress suggests:
pn  default-mysql-server | virtual-mysql-server  <none>
pn  php-curl                                     <none>
pn  php-imagick                                  <none>
pn  php-mbstring                                 <none>
pn  php-ssh2                                     <none>
ii  php-xml                                      2:8.4+96
pn  php-zip                                      <none>
ii  php8.4-xml [php-xml]                         8.4.23-1~deb13u1

--- End Message ---
--- Begin Message ---
Source: wordpress
Source-Version: 6.8.6+dfsg1-0+deb13u1
Done: Craig Small <[email protected]>

We believe that the bug you reported is fixed in the latest version of
wordpress, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated wordpress package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 21 Jul 2026 16:46:23 +1000
Source: wordpress
Architecture: source
Version: 6.8.6+dfsg1-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1142510
Changes:
 wordpress (6.8.6+dfsg1-0+deb13u1) trixie-security; urgency=medium
 .
   * New upstream security release 6.8.6
   * CVE-2026-60137 fix facilitated SQL injection Closes: #1142510
   * Includes release 6.8.4 and 6.8.5 updates
     - Check permissions on edit notes CVE-2026-3906 (not vulnerable)
Checksums-Sha1:
 86ad2320a06f96f2c0208ec1dd30fd9a1d230f40 2454 
wordpress_6.8.6+dfsg1-0+deb13u1.dsc
 801ef7748ced4da04f426f5dceef72371c07051b 22353380 
wordpress_6.8.6+dfsg1.orig.tar.xz
 b8f881557349979d02732fd7d23a8466a01ec264 6913388 
wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
 1f92ee113f746ef19ce01e297c44c5f2764e61aa 7762 
wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
 751c842edf129ba381c37e43b395ae1c7dbeff98fb0091316ee2943ad819ebeb 2454 
wordpress_6.8.6+dfsg1-0+deb13u1.dsc
 c1673d6833400e9c7bd76f95de5046bc7e5cdc523eafff219ba100761542c624 22353380 
wordpress_6.8.6+dfsg1.orig.tar.xz
 a82e4d7c0fe6b7b7687bf70125792b515947ce765f8c04bd7f430c31a0188a18 6913388 
wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
 46a57b4288f3c1d435d4f359e0ea9175a2b5b41329244faf8e4215197d65964d 7762 
wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo
Files:
 a2d21c07d60039cd8e78b91fec910c11 2454 web optional 
wordpress_6.8.6+dfsg1-0+deb13u1.dsc
 69173a72348b2ed003958b78846cce3f 22353380 web optional 
wordpress_6.8.6+dfsg1.orig.tar.xz
 9999da2d469430a32399b3ae707d0d63 6913388 web optional 
wordpress_6.8.6+dfsg1-0+deb13u1.debian.tar.xz
 0c13b6a677fe0edae5a38f73c1cb0a44 7762 web optional 
wordpress_6.8.6+dfsg1-0+deb13u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmpiDzEACgkQAiFmwP88
hONiJw/+PHxii5BRvgiZLAlWTtbTP0TtSuRQq6XAPoo50Xq2Th6mfs6QCRL58W2v
AwKz1Ws5xe4wC7G+zeDFQ1DldW++yZyxi6FQpCtEa2p9teaWSBBGPbse7PtylxGV
pxiew5ZbgiYarL0rqKvw9Kt+4+W9VR9VsmYF21LFn3TKDDgPfWp7fAji//ccMK9D
3fS3KMNC85Anl64hB6H41SezwVSYLY4QnSZ6Bh22O0L8ghjsvdSdjJFBPGULL2m7
VvQcamxvPkwaJeLZCnco4EOQrHTaA89TGLvA3jzXWoHT7vNavuRV1pP3flZTGXQI
bgmHYNZYaQevlJqQQwZ3AHL+bzNpFBSC6c/oAochV06zRPYxW8vUYcJN8nyDDRrR
zCEi58JNwuYeEhAsTtrnv7Io8hk1TRk1zXm/DRCt7jYf0iRAhsuRFofL12yiFBmI
6FLKIq8kJA3ZPXZQEDk/8ZA7mQdH56Z8NBKSz2j0l5bWqHliRIyEy6sRfHNOrnzJ
KS6i8dF2TuqXDvkt/1YuFAsBOumaBR+p5PpZYdn4b6LX/aKhjuYbctTrOoAnD9Qy
o7VVwfvMSVi8UOvtL6FgpOGOtYVDb1Ne0TgwbUogozQ3RJCxn2V0E6rcKLQTP7vA
SMUSJjAjtwr5YdftuPVqeIiv/5k3egfL8HpEfBCzEzyZCSV69LU=
=fJng
-----END PGP SIGNATURE-----

Attachment: pgpR1n79x1RT6.pgp
Description: PGP signature


--- End Message ---

Reply via email to