Aggregator

USN-8806-1: NetworkManager vulnerability

4 days 6 hours ago
It was discovered that NetworkManager did not properly restrict the ca-path and phase2-ca-path certificate authority settings for private (single-user) 802.1X network connections. An attacker could use this issue to point their own private 802.1X connection profile at a directory under their control, causing NetworkManager to trust an attacker-chosen certificate authority and potentially exposing network credentials via a rogue authentication server.

hplip-3.26.6-1.fc44

4 days 7 hours ago
FEDORA-2026-9e80aed94f Packages in this update:
  • hplip-3.26.6-1.fc44
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097

hplip-3.26.6-1.fc45

4 days 7 hours ago
FEDORA-2026-ebccf08143 Packages in this update:
  • hplip-3.26.6-1.fc45
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097

wordpress-6.9.9-1.fc44

4 days 15 hours ago
FEDORA-2026-7f9c69a63c Packages in this update:
  • wordpress-6.9.9-1.fc44
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.9-1.el10_2

4 days 15 hours ago
FEDORA-EPEL-2026-fa7b2ec3a3 Packages in this update:
  • wordpress-6.9.9-1.el10_2
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.9-1.fc43

4 days 15 hours ago
FEDORA-2026-5c9d8e41a9 Packages in this update:
  • wordpress-6.9.9-1.fc43
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.9-1.el9

4 days 15 hours ago
FEDORA-EPEL-2026-c032162b28 Packages in this update:
  • wordpress-6.9.9-1.el9
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.2-1.el10_3

4 days 15 hours ago
FEDORA-EPEL-2026-14c20cf8b8 Packages in this update:
  • wordpress-7.1.2-1.el10_3
Update description: WordPress 7.1.2 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.2-1.fc45

4 days 15 hours ago
FEDORA-2026-c7024b3255 Packages in this update:
  • wordpress-7.1.2-1.fc45
Update description: WordPress 7.1.2 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.2-1.el10_4

4 days 15 hours ago
FEDORA-EPEL-2026-9a22fff830 Packages in this update:
  • wordpress-7.1.2-1.el10_4
Update description: WordPress 7.1.2 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.