WordPress.org News
wordpress-org-news · A · candidate
ADDED as candidate by the 2026-07-18 weekly quality audit: WordPress core security releases (e.g. 7.0.2 / WP2Shell pre-auth RCE chain, 2026-07-17) had no curated discovery path; the release post is the vendor-primary for core CVEs affecting the huge Swiss/EU public-sector WordPress estate. Low cadence, high signal on security releases; the news feed carries them all. Promote to active after 3 contributing runs. | 2026-07-27 intel run: FIRST successful fetch since being added (rotation priority cleared) via the documented feed https://wordpress.org/news/feed/, ten items spanning 2026-06-06 to 2026-07-22, none in-window. 200-but-quiet: last_successful_fetch set, consecutive_quiet_periods incremented to 1.
Cited in 2 entries
Citation cadence
Citation days per ISO week (5 weeks of coverage span, total 2).
- CVE-2026-64638 (XSS2Shell), WordPress Core: a sanitiser disagreement on the login screen chains through DOM clobbering and a JSONP callback into administrator-minted Application Passwords and plugin upload2026-08-10
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18