Tag: CVE-2026-60137

  • WordPress 7.0.2 for Debian

    I have just uploaded WordPress version 7.0.2 for Debian. This fixes two serious security bugs CVE-2026-60137 and CVE-2026-63030. Chained together, this gives a RCE and is in active exploitation, so update as soon as its available.

    These two bugs are also in WordPress 6.9.x below 6.9.5 and the SQLi one (CVE-2026-60137) only is in 6.8.x below 6.8.6. Debian Sid and Forky have 7.0 which is vulnerable to the RCE while Debian Trixie has 6.8.x so only the SQLi.

    Updates for Trixie have been sent to the security team for review and once they’re happy I’ll upload for Trixie as well.

    Fediverse Reactions