wordpress-6.9.6-1.fc43
- wordpress-6.9.6-1.fc43
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters