|
#53973
|
WordPress <= 5.8 - Authenticated Persistent XSS (User role name)
|
|
Security
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
03/12/2025
|
|
#42733
|
WordPress Embed URLs don't work for draft and scheduled posts with pretty permalinks
|
|
Embeds
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/07/2024
|
|
#52740
|
WordPress Importer: Add vertical space between inputs
|
|
Import
|
normal
|
normal
|
WordPress.org
|
defect (bug)
|
has-patch
|
04/08/2021
|
|
#28474
|
WordPress destroys animation in animated GIF when it resizes
|
|
Media
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
01/29/2026
|
|
#50692
|
WordPress v5.4.2 Escaping Problem in the Edit Media Screen
|
|
Media
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
01/31/2023
|
|
#34839
|
Wrong attribution of current_page_parent for menus when on single/archive CPT
|
|
Menus
|
normal
|
normal
|
|
defect (bug)
|
needs-unit-tests
|
06/21/2025
|
|
#43502
|
`WP_REST_Posts_Controller::prepare_item_for_response()` doesn't reset postdata after calling setup_postdata()
|
|
REST API
|
normal
|
normal
|
Future Release
|
defect (bug)
|
needs-unit-tests
|
08/02/2025
|
|
#42096
|
`WP_Term_Query` sanitizes `slug` parameter incorrectly
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
10/11/2017
|
|
#40695
|
`install_blog` suppresses database errors
|
|
Database
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
06/01/2017
|
|
#62389
|
add_image_size "crop" does not crop
|
|
Media
|
normal
|
minor
|
Future Release
|
defect (bug)
|
has-patch
|
11/25/2024
|
|
#28314
|
cancel_comment_reply_link() is unflexible - respond_id & post check
|
|
Comments
|
normal
|
major
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#39338
|
class-wp-hook.php - apply_filters() infinite loop
|
|
Plugins
|
normal
|
critical
|
Future Release
|
defect (bug)
|
has-patch
|
08/01/2019
|
|
#34872
|
dbDelta Missing Index Name Creates Duplicate Indexes
|
|
Database
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#40694
|
dbDelta uses suppressed errors to detect table absence
|
|
Database
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
12/01/2019
|
|
#39461
|
default-preset option for custom background cannot be set by default
|
|
Customize
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/24/2021
|
|
#38997
|
delete_private_posts capability doesn't prevent user from deleting private posts
|
|
Role/Capability
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
03/19/2025
|
|
#33053
|
download_url() includes query string in temporary filenames
|
|
Upgrade/Install
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
02/21/2017
|
|
#28616
|
ftp_fput should have a retry threshold
|
|
Filesystem API
|
normal
|
normal
|
|
defect (bug)
|
needs-unit-tests
|
06/04/2019
|
|
#28163
|
function email_exists() check without removing umlauts
|
|
Users
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
07/26/2022
|
|
#37103
|
get_comments_number_text() should not replace '%' in post title
|
|
Comments
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#33498
|
get_home_path does not stripslashes $_SERVER['SCRIPT_FILENAME'] before using it
|
|
General
|
normal
|
normal
|
|
defect (bug)
|
needs-unit-tests
|
06/04/2019
|
|
#28488
|
get_post_type_object on CPT in _count_posts_cache_key after a wp_insert_post returns null
|
|
Posts, Post Types
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#33561
|
get_transient() will always return the value of a broken transient
|
|
Options, Meta APIs
|
normal
|
normal
|
|
defect (bug)
|
needs-unit-tests
|
06/04/2019
|
|
#39356
|
grunt precommit doesn't work on full checkouts of develop.svn
|
|
Build/Test Tools
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/18/2017
|
|
#30459
|
is_child_theme() cannot be used during plugin activation as is
|
|
Themes
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#31711
|
is_front_page flag affected by frontpage ID and page Title strange conflict
|
|
General
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
09/06/2024
|
|
#31935
|
is_page() erroneously set to true when loading /feed/ associated with 404
|
|
Feeds
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#39991
|
jQuery UI Datepicker Localization Error with PHP date 'S'
|
|
Script Loader
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
10/25/2018
|
|
#33521
|
manage_${post_type}_posts_columns parameters shifted
|
|
Taxonomy
|
normal
|
minor
|
|
defect (bug)
|
has-patch
|
06/22/2025
|
|
#61220
|
manage_media_columns filter conflict
|
|
Media
|
normal
|
major
|
Future Release
|
defect (bug)
|
has-patch
|
09/08/2024
|
|
#34358
|
plugin_dir_url( __FILE__ ) returns plugins directory when plugin symlinked to mu-plugins
|
|
Plugins
|
normal
|
normal
|
Future Release
|
defect (bug)
|
needs-unit-tests
|
10/02/2017
|
|
#51471
|
pre_oembed_result filter missing from oembed proxy controller
|
|
Embeds
|
normal
|
normal
|
Future Release
|
defect (bug)
|
needs-unit-tests
|
02/17/2021
|
|
#28026
|
previous_post_link returns incorrect post when posts have the same published date
|
|
Themes
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#64376
|
redirect_canonical() causes unnecessary 301 redirects for query string encoding variants (+ vs %20)
|
|
Canonical
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
03/06/2026
|
|
#34353
|
redirect_canonical() – Undefined indexes 'host' and 'scheme'
|
|
Canonical
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
08/29/2025
|
|
#24157
|
safecss_filter_attr doesn't allow rgb() in inline styles
|
|
Formatting
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
06/09/2024
|
|
#59361
|
update_post_meta() strict checks can cause false negatives
|
|
Options, Meta APIs
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/07/2025
|
|
#45047
|
user_registered returned as UTC Time instead of Local Time
|
|
Date/Time
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
04/22/2020
|
|
#31577
|
wp.ajax.send JS function should send ajax request with dataType json
|
|
General
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#32856
|
wpColorPicker close should check that iris hasn't been destroyed before toggling it.
|
|
General
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#40497
|
wp_insert_user requires user_login when ID is given
|
|
Users
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
05/19/2017
|
|
#27326
|
wp_list_pages - exclude parameter changes behaviour depending on depth
|
|
Posts, Post Types
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/23/2025
|
|
#43413
|
wp_prepare_attachment_for_js missing image size medium_large
|
|
Media
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
11/03/2024
|
|
#28145
|
wp_terms_checklist() returns all non-hierarchical terms even with $descendants_and_self parameter
|
|
Posts, Post Types
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#36931
|
wp_upload_dir caches calls with default arguments separately from their explicit equivalent
|
|
Media
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#40590
|
wp_video_shortcode always adds controls="controls"
|
|
Media
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
06/14/2025
|
|
#38656
|
wpautop incorrectly handling paragraphs within block elements
|
|
Formatting
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
01/29/2026
|
|
#37508
|
wpdb->result instance should be checked `mysqli_num_fields` in `load_col_info()`
|
|
Database
|
normal
|
normal
|
|
defect (bug)
|
needs-unit-tests
|
06/04/2019
|
|
#29882
|
wptexturize: quotes inside quotes curling incorrectly
|
|
Formatting
|
normal
|
normal
|
|
defect (bug)
|
has-patch
|
06/04/2019
|
|
#48954
|
"Sticky" post state shows even for non-Post post-types
|
|
Posts, Post Types
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
10/16/2025
|
|
#35858
|
"wpmu_welcome_notification" has a filter post-processing routines in wrong place
|
|
Login and Registration
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#31624
|
$wpdb->prepare() named placeholders
|
|
Database
|
normal
|
normal
|
|
enhancement
|
needs-unit-tests
|
06/22/2023
|
|
#34853
|
A helper method should be created to centralize which extensions are used for images.
|
|
General
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#35385
|
Able to get raw content by calling get_the_archive_description
|
|
Taxonomy
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/07/2020
|
|
#32508
|
Action Hooks for empty username and empty password
|
|
Login and Registration
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#28528
|
Action in wp-login.php
|
|
Login and Registration
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#32192
|
Add HTML attribute builder helper function
|
|
General
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#49381
|
Add Javascript Documentation to privacy-tools.js
|
|
Privacy
|
normal
|
normal
|
Future Release
|
enhancement
|
needs-docs
|
06/13/2025
|
|
#33600
|
Add `theme_mods_{$stylesheet}` option during `populate_options()`
|
|
Themes
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
05/07/2025
|
|
#28085
|
Add a "Recently Updated" Plugins' view
|
|
Plugins
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
08/11/2021
|
|
#33915
|
Add a filter in dynamic_sidebar() function to modify sidebar index
|
|
Widgets
|
normal
|
normal
|
|
enhancement
|
needs-unit-tests
|
06/05/2019
|
|
#62101
|
Add a filter to customize the URL for page caching check in Site Health
|
|
Site Health
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/25/2025
|
|
#35491
|
Add a function to check whether a hook is scheduled
|
|
Cron API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
06/04/2019
|
|
#29379
|
Add a hook to filter gallery classes
|
|
Gallery
|
low
|
normal
|
Future Release
|
enhancement
|
has-patch
|
05/05/2024
|
|
#34487
|
Add a new conditional tag for the "Posts Page"
|
|
General
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#38097
|
Add ability to Settings API to assign positioning
|
|
Administration
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
06/01/2021
|
|
#28094
|
Add action hook after getting template part
|
|
Themes
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#37459
|
Add additional layer in WP_Http to support parallel requests without requiring use of Requests directly
|
|
HTTP API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
08/27/2025
|
|
#33714
|
Add custom post types to the 'At a Glance' widget
|
|
Posts, Post Types
|
low
|
normal
|
|
enhancement
|
needs-docs
|
06/24/2024
|
|
#54513
|
Add meta support to template REST API
|
|
REST API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
11/25/2021
|
|
#46884
|
Add option to allow individual child-site Privacy Policy pages on multisite
|
|
Privacy
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
10/16/2020
|
|
#13874
|
Add package argument to "_deprecated_function" function
|
|
Bootstrap/Load
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
01/23/2025
|
|
#36978
|
Add pre filter to get_term_by
|
|
Taxonomy
|
normal
|
normal
|
|
enhancement
|
needs-unit-tests
|
06/04/2019
|
|
#54642
|
Add prepared query builder support for `$wpdb` to build prepared queries across multiple location.
|
|
Database
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
09/19/2022
|
|
#53520
|
Add regression test for the wp_option data corruption bug
|
|
Build/Test Tools
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/12/2025
|
|
#27316
|
Add search for favourite plugins
|
|
Plugins
|
normal
|
normal
|
|
enhancement
|
has-patch
|
03/11/2022
|
|
#64155
|
Add stack trace to failed plugin update error notifications
|
|
Upgrade/Install
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/03/2026
|
|
#38071
|
Add status links to network/sites.php
|
|
Networks and Sites
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
05/06/2017
|
|
#63231
|
Add support for batching GET REST API Requests
|
|
REST API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
04/04/2025
|
|
#59791
|
Add test for get_tag_regex
|
|
General
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/25/2025
|
|
#52613
|
Add testing setup instructions on wordpress-develop repository readme
|
|
Build/Test Tools
|
normal
|
minor
|
Future Release
|
enhancement
|
has-patch
|
11/10/2021
|
|
#59781
|
Add tests for wp_delete_file_from_directory
|
|
Filesystem API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/12/2025
|
|
#62866
|
Adjust background alternate row on post and page tables
|
|
Administration
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
09/02/2025
|
|
#56886
|
Admin facing add site screen missing search engine visibility field
|
|
Networks and Sites
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
02/12/2024
|
|
#37219
|
Admin menu with admin_url function
|
|
Administration
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#37041
|
Allow arbitrary return redirects when activating plugins
|
|
Plugins
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#38636
|
Allow data attributes to be added to WP Admin Bar menu items
|
|
Toolbar
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
04/08/2025
|
|
#41270
|
Allow deletion of plugins or themes from the Updates screen
|
|
Upgrade/Install
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
08/31/2018
|
|
#37349
|
Allow sanitize_meta() to filter the meta_value regardless of meta_key
|
|
Options, Meta APIs
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#54018
|
Allow scripts registered via block.json to be enqueued in the footer
|
|
Script Loader
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
10/16/2025
|
|
#30128
|
Allow to use associative arrays beside indexed arrays in wp_mail $headers
|
|
Mail
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
10/15/2025
|
|
#35384
|
Archive for post in Menu Editor
|
|
Menus
|
normal
|
normal
|
|
enhancement
|
needs-unit-tests
|
06/04/2019
|
|
#31960
|
Archives widget li should have informative css classes
|
|
Widgets
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/05/2019
|
|
#39318
|
Assign a theme when creating a site (Multisite)
|
|
Networks and Sites
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
06/14/2025
|
|
#31094
|
Attempt to cache notoptions in database to save queries for non-existent options
|
|
Options, Meta APIs
|
normal
|
normal
|
|
enhancement
|
needs-unit-tests
|
06/04/2019
|
|
#49616
|
Audit /wp-admin and sentence-case UI elements (buttons, drop-downs) for better readability
|
|
Administration
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
01/19/2021
|
|
#35983
|
Better support for "singular" endpoints
|
|
Rewrite Rules
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#35274
|
Break-out conditional in allow_subdomain_install()
|
|
Networks and Sites
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#37296
|
Bulk edit category labels are slightly misleading
|
|
Quick/Bulk Edit
|
normal
|
normal
|
|
enhancement
|
has-patch
|
06/04/2019
|
|
#28759
|
Cache API unit tests should verify public function, not WP_Object_Cache methods
|
|
Cache API
|
normal
|
normal
|
Future Release
|
enhancement
|
has-patch
|
07/08/2022
|