Dear Debian Security enthusiasts,
On https://security-tracker.debian.org/tracker/CVE-2026-60137 this CVE
is classified as: NOT-FOR-US: WordPress plugin
However, when I check the patch
https://github.com/WordPress/WordPress/compare/6.8.5...6.8.6 against
wordpress 6.8.3+dfsg1-0+deb13u1 I see the vulnerable code is delivered
by the core wordpress dpkg in wp-includes/class-wp-query.php
Please change the classification of CVE-2026-60137 and apply the patch
since this CVE is being actively exploited.
Kind regards,
Richard van den Berg