The ‘Must-Patch’ Release: WordPress 6.9.2 Scrambles to Fix 10 Critical Flaws from XSS to SSRF
ID: 67876759-0834-5ec1-adc6-5c833116479f
STIX ID: report--67876759-0834-5ec1-adc6-5c833116479f
Feed Name: securityonline.info
Threat Score
WordPress released version 6.9.2 on March 10, 2026, a security-focused update that addresses ten vulnerabilities—including a PclZip path traversal, an XXE in getID3, authorization bypasses, several XSS vectors, a Regex DoS, blind SSRF, and a PoP-chain weakness in the HTML API/Block Registry—with fixes backported to supported branches as far back as 4.7; administrators are strongly urged to apply the update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
