Package: wordpress Version: 7.0+dfsg1-1 Severity: grave Tags: security Justification: user security hole X-Debbugs-Cc: Debian Security Team <[email protected]>
WordPress versions 6.9 and higher are vulnerable to a REST API batch-route confusion weakness, which combined with an SQL injection issue (GHSA-fpp7-x2x2-2mjf) leads to Remote Code Execution. WordPress versions 7.0.2, 6.9.5, and 7.1 beta2 have been released, containing fixes for the vulnerability. References: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ -- System Information: Debian Release: 13.6 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable-debug'), (500, 'stable'), (50, 'unstable') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 6.12.95+deb13-amd64 (SMP w/12 CPU threads; PREEMPT) Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8), LANGUAGE=en_AU:en Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages wordpress depends on: ii apache2 [httpd] 2.4.68-1~deb13u1 ii ca-certificates 20250419 pn default-mysql-client | virtual-mysql-c <none> lient pn libapache2-mod-php | php <none> pn libjs-cropper <none> ii libjs-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9 ii libjs-underscore 1.13.4~dfsg+~1.11.4-3 pn php-gd <none> pn php-getid3 <none> pn php-mysql | php-mysqlnd <none> Versions of packages wordpress recommends: pn wordpress-l10n <none> pn wordpress-theme-twentytwentyfive <none> Versions of packages wordpress suggests: pn default-mysql-server | virtual-mysql-server <none> pn php-curl <none> pn php-imagick <none> pn php-mbstring <none> pn php-ssh2 <none> ii php-xml 2:8.4+96 pn php-zip <none> ii php8.4-xml [php-xml] 8.4.23-1~deb13u1

