[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6399-1] wordpress security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6399-1] wordpress security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Thu, 23 Jul 2026 21:19:11 +0000 Message-id: <[🔎] E1wn0ox-00000004ImB-0Qcx@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6399-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 23, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wordpress CVE ID : CVE-2026-60137 Debian Bug : 1142510 It was discovered that wordpress, a web blogging tool, was prone to a SQL injection vulnerability. For the stable distribution (trixie), this problem has been fixed in version 6.8.6+dfsg1-0+deb13u1. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wordpress Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpihQ5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SIFQ/9GpuQd3zru1hMPgeY7b+6D//Pf0vn0rw7sDK7y1QNLCo4iDahYbwdcPXI M4uKp9V9Iy8wPZc+jbqBIe02ul21VBHLvSurwNVHMQoPRtnIvD7yU3Wt742rZ35F fBDjHR086DtpmxwxpccErytH94OI1NWNx50/podHsYoWL89WWoYJ3C8fxyqq4YfK DvjH6yzk7VY714W/ae0oTc+/1kDwt5SIE+bGpnZ16bnEhq3x/Cw+y76xu4PBzIn7 Ch6CbdUryYtjZqrqvMcTrm6HomzEsqpt/dmesOEgoLNs/1qMUwax70ECeukjG0lK CSVBw/LlHszv8mX+rzE12lCI4aOeEi2iDzNljYJMVp4FkHifo7pf1qA9SWJJb3BK laWysVe+KvL7/68TNIIFak+0qBAse2Weoyoipe1gmciIIak6aNNfiRLgIBEv8rRi +mm195NDCdSRVLpuNS0XqsT4M7s/ifMXvcCezrvJ79xhkOM46SLmNJVKYxsi+CsH Han/3oWuuev7142XlhLg96PMnZ23lHh2skKl4tCsgWZU+2K6VTMooVCQDfZt1K9z bQ9tYHvfWs059IgXCV6MSVh+QUgCo5TP1XslDnwDu8FNB35uj5TGTy6lCap7OukO ed0RCchV+06CIw93dD/+TxU8DQVJCLCzlRkyV/gM6tyoNqrAuu0= =JLLf -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6398-1] webkit2gtk security update Previous by thread: [SECURITY] [DSA 6398-1] webkit2gtk security update Index(es): Date Thread
This security update addresses a SQL injection vulnerability (CVE-2026-60137, CVSS 5.9 MEDIUM) in WordPress. The vulnerability affects WordPress versions 6.8 through 6.8.6, 6.9 through 6.9.5, and 7.0 through 7.0.2. Users must upgrade to version 6.8.6, 6.9.5, or 7.0.2, respectively, to remediate the issue.