wordpress-6.9.8-1.el10_2
- wordpress-6.9.8-1.el10_2
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.