logo

The ‘Must-Patch’ Release: WordPress 6.9.2 Scrambles to Fix 10 Critical Flaws from XSS to SSRF

ID: 67876759-0834-5ec1-adc6-5c833116479f

STIX ID: report--67876759-0834-5ec1-adc6-5c833116479f

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

WordPress released version 6.9.2 on March 10, 2026, a security-focused update that addresses ten vulnerabilities—including a PclZip path traversal, an XXE in getID3, authorization bypasses, several XSS vectors, a Regex DoS, blind SSRF, and a PoP-chain weakness in the HTML API/Block Registry—with fixes backported to supported branches as far back as 4.7; administrators are strongly urged to apply the update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.