CVE-2026-60137 wordpress vulnerability

Richard van den Berg <[email protected]> Mon, 20 Jul 2026 11:17:37 +0200
Newsgroups gmane.linux.debian.devel.security,gmane.linux.debian.security.tracker
Message-ID <[email protected]>
Dear Debian Security enthusiasts,

On https://security-tracker.debian.org/tracker/CVE-2026-60137 this CVE 
is classified as: NOT-FOR-US: WordPress plugin

However, when I check the patch 
https://github.com/WordPress/WordPress/compare/6.8.5...6.8.6 against 
wordpress 6.8.3+dfsg1-0+deb13u1 I see the vulnerable code is delivered 
by the core wordpress dpkg in wp-includes/class-wp-query.php

Please change the classification of CVE-2026-60137 and apply the patch 
since this CVE is being actively exploited.

Kind regards,

Richard van den Berg