wordpress-6.9.10-1.el9
- wordpress-6.9.10-1.el9
Security updates included in this release
- A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
- A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
- A second-Order SQL injection in WordPress WXR export, reported by Anthropic
- A weakness allowing Author role users to sticky posts, reported by Anthropic
- Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
- Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
- Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team