Dear Debian Security enthusiasts,

On https://security-tracker.debian.org/tracker/CVE-2026-60137 this CVE is classified as: NOT-FOR-US: WordPress plugin

However, when I check the patch https://github.com/WordPress/WordPress/compare/6.8.5...6.8.6 against wordpress 6.8.3+dfsg1-0+deb13u1 I see the vulnerable code is delivered by the core wordpress dpkg in wp-includes/class-wp-query.php

Please change the classification of CVE-2026-60137 and apply the patch since this CVE is being actively exploited.

Kind regards,

Richard van den Berg

Reply via email to