Aggregator

wordpress-7.1.2-1.fc45

3 days 11 hours ago
FEDORA-2026-c7024b3255 Packages in this update:
  • wordpress-7.1.2-1.fc45
Update description: WordPress 7.1.2 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.2-1.el10_4

3 days 11 hours ago
FEDORA-EPEL-2026-9a22fff830 Packages in this update:
  • wordpress-7.1.2-1.el10_4
Update description: WordPress 7.1.2 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

apptainer-1.5.4-1.fc44

3 days 22 hours ago
FEDORA-2026-e84de41d80 Packages in this update:
  • apptainer-1.5.4-1.fc44
Update description:

Update to upstream 1.5.4, including fix for high severity vulnerability GHSA-cr2j-534f-mf3g and for CVE-2026-41178.

apptainer-1.5.4-1.el8

3 days 22 hours ago
FEDORA-EPEL-2026-fb3f4867a1 Packages in this update:
  • apptainer-1.5.4-1.el8
Update description:

Update to upstream 1.5.4, including fix for high severity vulnerability GHSA-cr2j-534f-mf3g and for CVE-2026-41178.

apptainer-1.5.4-1.el10_2

3 days 22 hours ago
FEDORA-EPEL-2026-5d2ba07938 Packages in this update:
  • apptainer-1.5.4-1.el10_2
Update description:

Update to upstream 1.5.4, including fix for high severity vulnerability GHSA-cr2j-534f-mf3g and for CVE-2026-41178.