-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dc0ff85b8b 2026-08-21 05:18:12.044297+00:00 --------------------------------------------------------------------------------
Name : wordpress Product : Fedora 44 Version : 6.9.7 Release : 1.fc44 URL : https://wordpress.org/ Summary : Blog tool and publishing platform Description : Wordpress is an online publishing / weblog package that makes it very easy, almost trivial, to get information out to people on the web. Important information in /usr/share/doc/wordpress/README.fedora -------------------------------------------------------------------------------- Update Information: WordPress 6.9.7 Release Security update included in this release Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640 WordPress 6.9.6 Release Security update included in this release Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638 Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec) Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team Enumeration of post slugs reported by HDWSec Disclosure of notes in comment feeds reported by Elio Gubser Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic Bypass of the email address confirmation flow reported by 0ways A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters -------------------------------------------------------------------------------- ChangeLog: * Thu Aug 13 2026 Remi Collet <[email protected]> - 6.9.7-1 - WordPress 6.9.7 Security Release * Fri Aug 7 2026 Remi Collet <[email protected]> - 6.9.6-1 - WordPress 6.9.6 Security Release -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dc0ff85b8b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
