Security component

If you have encountered a security issuesecurity issue A security issue is a type of bug that can affect the security of WordPress installations. Specifically, it is a report of a bug that you have found in the WordPress core code, and that you have determined can be used to gain some level of access to a site running WordPress that you should not have. that isn’t addressed in a released version of WordPress, please report it to the WordPress HackerOne program. For more, see our Security FAQ in the handbook.

Recent posts on the make/core blog

View all posts tagged security.

56 open tickets in the Security component

56 open ticketsdefect (bug)enhancementfeature requesttask (blessed)
3000
Awaiting Review181740
Future Release1731
7.20200
56 open tickets. Last 7 days: +0 tickets

12 tickets that have no replies

View list on Trac
  • #51611  Escape echoing Core functions
  • #53994  REST API requests with session cookies but an invalid/missing nonce are considered authenticated for most of the request rest-api
  • #56860  Sodium Compat library is improperly loaded
  • #57424  Specific hook for Content Security Policy
  • #57447  wp_ajax_inline_save function does not check if post has "public" or "show_ui" enabled
  • #58636  Automatic Sanitization of Nonces in wp_verify_nonce coding-standards
  • #58679  meta key field in usermeta table should NOT use accent insensitive collations
  • #62693  check if chmod is available to prevent Fatal Errors
  • #62949  HttpOnly flag for the post password cookie
  • #63940  Prevent POST flood cache bypass attacks
  • #64481  Explore Sec-Fetch Headers as a Core-Supported CSRF Mitigation Mechanism
  • #66054  Unauthenticated XML-RPC pingback timing oracle discloses non-public post titles and privacy-request email addresses

2 tickets slated for 7.2

View list in Trac
  • #37000  Support for the SameSite cookie attribute administration
  • #66187  Secrets API: encrypted, versioned storage for credentials

56 open tickets

Open enhancements: 26 View list on Trac
Open tasks: 1 View list on Trac
Open feature requests: 7 View list on Trac
Open defects: 22 View list on Trac

Help maintain this component

Component maintainers:

Many contributors help maintain one or more components. These maintainers are vital to keeping WordPress development running as smoothly as possible. They triage new tickets, look after existing ones, spearhead or mentor tasks, pitch new ideas, curate roadmaps, and provide feedback to other contributors. Longtime maintainers with a deep understanding of particular areas of Core are always seeking to mentor others to impart their knowledge.

Want to help? Start following this component! Adjust your notifications here. Feel free to dig into any ticket.

Contributors following this component: