#50027
|
Retire Phpass and use PHP native password hashing
|
|
needs-unit-tests
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
10/13/2023
|
#56860
|
Sodium Compat library is improperly loaded
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
10/20/2022
|
#58771
|
Someone logged onto my WordPress Admin Site, changed the password, and created a User Registration
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
07/10/2023
|
#53019
|
The _sanitize_text_fields function removing the octets that incorrectly work with Arabic RTL languages.
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
03/14/2023
|
#59355
|
TypeError: Cannot read properties of undefined (reading 'hasClass') in wp-auth-check.min.js
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
09/15/2023
|
#50828
|
Update ca-bundle.crt and remove expired certificates
|
SergeyBiryukov
|
has-patch
|
normal
|
normal
|
Future Release
|
defect (bug)
|
11/10/2021
|
#57882
|
User that has capability to create user can make only administrator.
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
03/07/2023
|
#16483
|
Visibility: password-protected exposes multiple pages
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
01/30/2022
|
#48955
|
WP 5.3.1 changes cause potential backwards compatibility breakage with kses
|
|
|
normal
|
normal
|
Future Release
|
defect (bug)
|
08/12/2020
|
#53973
|
WordPress <= 5.8 - Authenticated Persistent XSS (User role name)
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
12/23/2022
|
#58916
|
Wrong User Password Reset
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
07/29/2023
|
#34852
|
fix broken re-auth loop (due to expired session)
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/04/2019
|
#55605
|
kses "selected" for option
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/15/2022
|
#57613
|
my client made changes to site without being a user
|
|
close
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
02/02/2023
|
#56391
|
safecss_filter_attr(): support rgba background-color
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
11/30/2022
|
#57447
|
wp_ajax_inline_save function does not check if post has "public" or "show_ui" enabled
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
01/11/2023
|
#31686
|
wp_authenticate_username_password() should check for a WP_Error object
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
08/06/2019
|
#37670
|
wp_validate_redirect fails when running WordPress on a port
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/04/2019
|
#38260
|
A FORCE_SSL_CANONICAL constant
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/04/2019
|
#38259
|
A FORCE_SSL_CONTENT constant
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/04/2019
|
#38261
|
A FORCE_SSL_SCRIPTS constant
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/04/2019
|
#57304
|
Add SensitiveParameter attribute to DB connection and login variables
|
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
02/28/2023
|
#37757
|
Add `allowed_classes` to `maybe_unserialize` When WordPress is running on PHP 7+
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
09/13/2017
|
#57875
|
Add password strength meter for password protected content
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
06/01/2023
|
#52639
|
Add proper Security Attributes to the Cookies set by WordPress
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/20/2022
|
#23165
|
Admin validation errors on form nonce element IDs (_wpnonce)
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/08/2021
|
#58636
|
Automatic Sanitization of Nonces in wp_verify_nonce
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/26/2023
|
#56785
|
Automatically catch potential security issues before release
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
10/11/2022
|
#39656
|
Create a submenu item under About admin bar for security
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
01/23/2017
|
#56160
|
Deprecate wp_sanitize_redirect
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
07/09/2022
|
#53296
|
Do trim $hook_name within add_action() and add_filter() function
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
05/29/2021
|
#40237
|
Educate users about modern password best-practices
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/06/2022
|
#51611
|
Escape echoing Core functions
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
10/24/2020
|
#28521
|
FORCE_SSL constant for really forcing SSL
|
adamsilverstein
|
|
normal
|
normal
|
Future Release
|
enhancement
|
06/08/2023
|
#50510
|
Improve security of wp_nonce implementation
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
07/11/2023
|
#44058
|
Include security sniffs in PHPCS ruleset
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
05/16/2018
|
#51159
|
Let's expand our context specific escaping methods for wp_json_encode().
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
08/27/2020
|
#36087
|
Migration plan from insecure RNG fallback
|
|
|
normal
|
normal
|
Future Release
|
enhancement
|
09/30/2020
|
#51407
|
Remove inline event handlers and JavaScript URIs for Strict CSP-compatibility
|
adamsilverstein
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
05/16/2023
|
#57424
|
Specific hook for Content Security Policy
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
01/05/2023
|
#54512
|
Suggestion for file protection
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
11/25/2021
|
#37000
|
Support for the SameSite cookie attribute
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
11/11/2022
|
#29429
|
Support frame-ancestors directive over X-Frame-Options
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
enhancement
|
07/29/2019
|
#38262
|
Task: Opt in SSL Improvements
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
02/05/2020
|
#51438
|
Use CSP directive upgrade-insecure-requests when using HTTPS
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
enhancement
|
11/09/2021
|
#52388
|
Use HTTPS URL already during installation if supported
|
|
needs-unit-tests
|
normal
|
normal
|
Future Release
|
enhancement
|
01/28/2021
|
#55067
|
Use of undefined constant ABSPATH - assumed 'ABSPATH' as of WP5.9
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
06/12/2023
|
#47440
|
add_header X-Frame-Options
|
|
close
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
05/31/2019
|
#36177
|
default htaccess should include security measures
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
11/09/2021
|
#58765
|
the_block_template_skip_link() - XSS vulnerability - Apply FIX
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
07/08/2023
|
#38474
|
wp_signups.activation_key stores activation keys in plain text
|
SergeyBiryukov
|
has-patch
|
normal
|
normal
|
Future Release
|
enhancement
|
01/08/2019
|
#54280
|
wp_verify_nonce should return a filter
|
|
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
10/17/2021
|
#37604
|
'Password Lost/Changed' emails should give indication of the strength of the new password
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
feature request
|
04/09/2018
|
#55514
|
2FA by default for WordPress
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
03/06/2023
|
#43215
|
Allow wp_kses to pass allowed CSS properties
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
02/02/2018
|
#20140
|
Ask old password to change user password
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
feature request
|
06/04/2019
|
#53902
|
Automating the creation of inline javascript and inline stylesheet nonces or hashes
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
01/03/2022
|
#30465
|
Dashboard alert if a plugin/theme was removed from WordPress repo
|
|
dev-feedback
|
normal
|
normal
|
6.5
|
feature request
|
09/18/2023
|
#38536
|
Hook/Function to Set Content-Security-Policy
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
06/04/2019
|
#55228
|
Provide Option to Remove Password Visibility Button and Dashicons from WordPress' Login Form
|
|
close
|
normal
|
normal
|
Awaiting Review
|
feature request
|
02/25/2022
|
#32067
|
Remove inline javascript from WP-Core to allow CSP protection
|
|
|
normal
|
normal
|
Future Release
|
feature request
|
09/28/2020
|
#50613
|
disable update for themes e plugin
|
|
|
normal
|
normal
|
Awaiting Review
|
feature request
|
07/09/2020
|
#50437
|
Add leniency to the overdue check for plugin and theme auto updates
|
|
|
normal
|
normal
|
Future Release
|
task (blessed)
|
07/14/2020
|
#15394
|
Ancient "Are you sure you want to do this" now confusing
|
|
dev-feedback
|
normal
|
minor
|
Future Release
|
defect (bug)
|
05/17/2019
|
#52333
|
Lack of the : entity on the list of allowed entity names in kses.php
|
|
has-patch
|
normal
|
minor
|
Awaiting Review
|
defect (bug)
|
01/20/2021
|
#43320
|
Harden API requests against man-in-the-middle attacks
|
|
|
low
|
minor
|
Awaiting Review
|
enhancement
|
02/18/2018
|
#55950
|
FIDO passwordless authentication?
|
|
|
normal
|
minor
|
Awaiting Review
|
feature request
|
06/08/2022
|
#58769
|
HTTP/3 Early-Data/0-RTT replay attack
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
07/10/2023
|
#60009
|
Potential SQL Injection in WordPress Core
|
|
needs-review
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
12/04/2023
|
#34041
|
Tying nonces to sessions breaks when users are switched
|
|
|
normal
|
major
|
Future Release
|
defect (bug)
|
06/04/2019
|
#58679
|
meta key field in usermeta table should NOT use accent insensitive collations
|
|
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
10/30/2023
|
#56521
|
wp_kses wp_kses_hair fails to allow a valueless attribute when is follwed by /
|
|
has-patch
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
09/06/2022
|
#56141
|
Enhance installer security
|
|
dev-feedback
|
high
|
major
|
Future Release
|
enhancement
|
09/09/2023
|
#52544
|
Removing database tables allows anyone to take over all website files
|
|
|
normal
|
major
|
Awaiting Review
|
enhancement
|
07/05/2022
|
#21022
|
Use bcrypt for password hashing; updating old hashes
|
|
dev-feedback
|
normal
|
major
|
Future Release
|
enhancement
|
05/08/2023
|
#43936
|
Settings: Warn when open registration and new user default is privileged
|
SergeyBiryukov
|
has-patch
|
normal
|
major
|
Future Release
|
feature request
|
03/30/2023
|
#46792
|
CPANEL Directory Privacy DoesNOT work With WordPress Admin Directory
|
|
reporter-feedback
|
normal
|
blocker
|
Awaiting Review
|
defect (bug)
|
04/05/2019
|
#58174
|
A shortcode block that evaluates to nothing, renders as a space in the HTML
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
10/26/2023
|
#58469
|
Changeset 55832 broke shortcodes saved in block attributes and rendered serverside
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/07/2023
|
#33134
|
Complex Nested Shortcodes Inside of Attributes Are Not Processed Left-to-Right
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#49877
|
Content enclosed by (content enclosing) shortcode gets stripped from excerpt
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
07/24/2020
|
#47863
|
Fix odd, unexpected output from shortcode_parse_attts
|
SergeyBiryukov
|
dev-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
02/24/2020
|
#51377
|
Front End elements break after too many shortcodes
|
|
reporter-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
09/24/2020
|
#43725
|
Multiple instances of opening / closing shortcode only works when closing tag is provided
|
|
|
normal
|
normal
|
Future Release
|
defect (bug)
|
07/16/2020
|
#24990
|
Nested Shortcode Inside [caption]
|
|
needs-unit-tests
|
normal
|
normal
|
|
defect (bug)
|
05/08/2021
|
#37183
|
Nested shortcodes in new-style [caption]
|
|
dev-feedback
|
normal
|
normal
|
|
defect (bug)
|
05/08/2021
|
#57790
|
Parsing of Shortcode Attributes: bug locating a final attribute
|
|
dev-feedback
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
02/28/2023
|
#45929
|
Potential assignment to empty string
|
swissspidy
|
close
|
normal
|
normal
|
6.5
|
defect (bug)
|
10/16/2023
|
#34814
|
Presence of "Less than sign" < adds additional closing shortcode tag.
|
|
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#35216
|
Return empty string from wp.shortcode.replace() callback is ignored
|
|
has-patch
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/27/2018
|
#37238
|
Right-aligned captions with embedded iframes get removed in Visual mode
|
|
|
normal
|
normal
|
|
defect (bug)
|
04/19/2019
|
#35591
|
Shortcode Attributes Parsing Issue
|
|
reporter-feedback
|
normal
|
normal
|
|
defect (bug)
|
06/04/2019
|
#58366
|
Shortcode Support Regained but Content Filters are messing with Shortcode HTML
|
|
needs-unit-tests
|
normal
|
normal
|
6.5
|
defect (bug)
|
12/04/2023
|
#59509
|
Shortcode attributes named 0 are ignored
|
|
needs-unit-tests
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
10/04/2023
|
#49955
|
Shortcode escaping not correctly handled when followed by enclosing shortcodes
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
07/16/2020
|
#58386
|
Shortcode generated by a block element is not executed in templates
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
06/09/2023
|
#38713
|
Shortcodes and utf-8 no-break whitespace (\xc2\xa0)
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
03/25/2019
|
#43686
|
Shortcodes containing asterisks may create invalid regex breaking the editor
|
|
dev-feedback
|
normal
|
normal
|
Future Release
|
defect (bug)
|
01/16/2019
|
#55406
|
Shortcodes don't work inside srcset attribute
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
04/08/2022
|
#58397
|
Shortcodes in patterns are not rendered in templates
|
|
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
05/24/2023
|