Skip to content

Update dependency roots/wordpress to v6.9.7 - #195

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/roots-wordpress-6.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/roots-wordpress-6.x

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
roots/wordpress (source) 6.9.4 → 6.9.7 age confidence

Release Notes

roots/wordpress (roots/wordpress)

v6.9.7: Version 6.9.7

Compare Source

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • An authenticated Author+ remote code execution issue via malicious file upload on sites that use Imagick and Ghostscript reported by the team at pwn.ai

v6.9.6: Version 6.9.6

Compare Source

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block reported by n05ec
  • A bypass of the email address confirmation flow reported by 0ways
  • An Author+ CSS injection issue via a bypass of the safe CSS attribute filter reported by Anthropic
  • A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
  • A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai
  • A disclosure of notes in comment feeds reported by Elio Gubser
  • An enumeration of post slugs reported by HDWSec
  • A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal

v6.9.5: Version 6.9.5

Compare Source

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber

As a courtesy, these fixes are available in affected branches of WordPress to eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the Dependency Indicates a dependency update label Oct 3, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 3, 2026

Copy link
Copy Markdown

@coveralls

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 37133708862

Coverage remained the same at 90.657%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 685
Covered Lines: 621
Line Coverage: 90.66%
Coverage Strength: 259.15 hits per line

💛 - Coveralls

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependency Indicates a dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants