From Salvatore Bonaccorso@21:1/5 to All on Mon Jul 21 22:20:01 2025
Source: wordpress
Version: 6.8.1+dfsg1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for wordpress.
CVE-2025-54352[0]:
| WordPress 3.5 through 6.8.2 allows remote attackers to guess titles
| of private and draft posts via pingback.ping XML-RPC requests. NOTE:
| the Supplier is not changing this behavior.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.