|
#51891
|
Multiple xmlrpc attacks after last update
|
|
XML-RPC
|
major
|
defect (bug)
|
01/07/2021
|
5.5.3
|
needs-patch
|
|
#44710
|
Upload plugin and theme functionalities are not removing uploaded files after failure conditions.
|
|
Administration
|
normal
|
defect (bug)
|
12/25/2020
|
4.9.7
|
needs-patch
|
|
#31751
|
Using PgDn and PgUp keyboard keys in the editor scrolls both post edit box and the whole viewport
|
|
Editor
|
normal
|
defect (bug)
|
11/24/2020
|
4.1.1
|
needs-patch
|
|
#31375
|
Image caption with heading adds an empty paragraph at page edits
|
|
Editor
|
normal
|
defect (bug)
|
11/24/2020
|
4.1
|
needs-patch
|
|
#51421
|
wp_get_missing_image_subsizes returns thumbnail sizes for animated GIFs
|
|
Media
|
normal
|
defect (bug)
|
10/01/2020
|
5.5.1
|
needs-patch
|
|
#50850
|
When the deactivate_plugins() function is called in the ABSPATH/wp-admin/includes/plugin.php file, the is_plugin_active_for_network() conditional tag always returns true when the active_sitewide_plugins sitemeta option is set to 1
|
|
Plugins
|
normal
|
defect (bug)
|
09/08/2020
|
5.4.2
|
needs-patch
|
|
#50726
|
Pagination error on 4 digit page when category and year are in the permalink structure
|
|
Rewrite Rules
|
minor
|
defect (bug)
|
07/21/2020
|
5.5
|
needs-patch
|
|
#50439
|
Post name permalinks htaccess directives do not consider subdirectory installation
|
|
Permalinks
|
normal
|
defect (bug)
|
06/20/2020
|
5.4.2
|
needs-patch
|
|
#50172
|
Flickr embed not embedding content
|
|
Embeds
|
normal
|
defect (bug)
|
05/15/2020
|
5.4.1
|
needs-patch
|
|
#50098
|
CSVs that contain HTML fail upload test
|
|
Upload
|
normal
|
defect (bug)
|
05/06/2020
|
|
needs-patch
|
|
#49820
|
Input and select elements are misaligned in the admin area
|
|
Administration
|
trivial
|
defect (bug)
|
04/13/2020
|
5.4
|
needs-patch
|
|
#49857
|
Groups disappear after inserting something inside it in Gutenberg
|
|
Editor
|
normal
|
defect (bug)
|
04/09/2020
|
5.4
|
needs-patch
|
|
#34683
|
Default .htaccess config creates rewrite infinite loops for path-based multisite installations
|
|
Rewrite Rules
|
normal
|
defect (bug)
|
03/27/2020
|
4.3.1
|
needs-patch
|
|
#49203
|
Requests::request_multiple() does not honor $auth option
|
|
HTTP API
|
normal
|
defect (bug)
|
02/05/2020
|
5.4
|
needs-patch
|
|
#49345
|
User with admin privileges cannot edit some pages/posts
|
|
Role/Capability
|
normal
|
defect (bug)
|
02/02/2020
|
5.3.2
|
needs-patch
|
|
#48915
|
Gutenberg Paragraph Block, Drop Cap missing sanitize rule for initial hard return line <br>
|
|
Editor
|
minor
|
defect (bug)
|
01/10/2020
|
5.3
|
needs-patch
|
|
#49044
|
Links in the text widget now require quotes
|
audrasjb
|
Widgets
|
normal
|
defect (bug)
|
01/07/2020
|
5.3.1
|
needs-patch
|
|
#49014
|
Silence set_time_limit() call in wp-admin/includes/class-wp-upgrader.php
|
|
Upgrade/Install
|
trivial
|
defect (bug)
|
12/24/2019
|
|
needs-patch
|
|
#48365
|
No 301 redirection for Numeric style permalink structure
|
|
Permalinks
|
normal
|
defect (bug)
|
11/11/2019
|
|
needs-patch
|
|
#48519
|
Comment reply form in admin incompatible with most custom fields plugins
|
|
Comments
|
normal
|
defect (bug)
|
11/06/2019
|
5.2.4
|
needs-patch
|
|
#48361
|
Select Files on iOS doesn't trigger on modal if start on Upload Files tab and switch to Media Library tab
|
adamsilverstein
|
Media
|
normal
|
defect (bug)
|
11/03/2019
|
|
needs-patch
|
|
#48048
|
Parent pages are not visible in the Page Attributes metabox
|
|
Administration
|
normal
|
defect (bug)
|
09/16/2019
|
5.2.3
|
needs-patch
|
|
#45130
|
Defer jQuery WordPress Admin & Customizer doesn't work properly
|
|
Administration
|
normal
|
defect (bug)
|
07/01/2019
|
|
needs-patch
|
|
#47618
|
Email sent to blank address on email change for user with no previous email address
|
|
Users
|
minor
|
defect (bug)
|
06/27/2019
|
|
needs-patch
|
|
#47470
|
XML parsing error: undefined entity (revisited)
|
|
Feeds
|
normal
|
defect (bug)
|
06/03/2019
|
5.2.1
|
needs-patch
|
|
#22150
|
Customizer: Remove Image doesn't remove from Media Library
|
|
Upload
|
normal
|
defect (bug)
|
05/15/2019
|
3.4
|
needs-patch
|
|
#37829
|
Problem when adding a link and searching published articles
|
|
Editor
|
normal
|
defect (bug)
|
04/19/2019
|
4.5
|
needs-patch
|
|
#43070
|
srcset attribute can be overridden but not prevented
|
|
Media
|
normal
|
defect (bug)
|
04/11/2019
|
4.4
|
needs-patch
|
|
#30497
|
Impossible to change upgrader skin when Language_Pack_Upgrader is instanciated via Language_Pack_Upgrader::async_upgrade()
|
|
Upgrade/Install
|
normal
|
defect (bug)
|
03/28/2019
|
4.0
|
needs-patch
|
|
#40221
|
switch_theme action + Live Preview = confusion
|
|
Themes
|
normal
|
defect (bug)
|
03/13/2019
|
4.7.3
|
needs-patch
|
|
#29066
|
Grunt clean:dynamic task does not delete file/s from /build during grunt watch task
|
|
Build/Test Tools
|
minor
|
defect (bug)
|
02/25/2019
|
3.7
|
needs-patch
|
|
#45970
|
in IIS if web.confing <configuration has xmlns="http://schemas.microsoft.com/.NetConfiguration/v2.0" attribute the WordPress creates new <configuration> section and the site craches with wrong web.config
|
|
Rewrite Rules
|
normal
|
defect (bug)
|
01/13/2019
|
5.0.3
|
needs-patch
|
|
#39140
|
Taxonomies - operator AND doesn't work properly for taxonomy hierarchies
|
|
Query
|
normal
|
defect (bug)
|
01/08/2019
|
4.6.1
|
needs-patch
|
|
#45687
|
URL params get lost because of canonical redirect on static front page
|
|
Canonical
|
minor
|
defect (bug)
|
12/18/2018
|
5.0.1
|
needs-patch
|
|
#45532
|
WordPress 5.0 preview does not show updated content
|
|
Editor
|
normal
|
defect (bug)
|
12/13/2018
|
5.0
|
needs-patch
|
|
#27832
|
All sites automatically marked as archived after upgrade
|
|
Networks and Sites
|
normal
|
defect (bug)
|
12/08/2018
|
3.7
|
needs-patch
|
|
#43641
|
Media controls in the media grid are too wide
|
|
Media
|
normal
|
defect (bug)
|
10/02/2018
|
4.9
|
needs-patch
|
|
#43310
|
Generic "HTTP Error" when uploading PDFs via Media area
|
|
Media
|
normal
|
defect (bug)
|
08/19/2018
|
4.9.4
|
needs-patch
|
|
#41388
|
Insert Media window does not remember state for custom tabs, iframe bug
|
|
General
|
critical
|
defect (bug)
|
08/14/2018
|
4.8
|
needs-patch
|
|
#42288
|
Validation of custom menu link
|
|
Menus
|
normal
|
defect (bug)
|
06/14/2018
|
4.8.2
|
needs-patch
|
|
#41035
|
Don't return if WP_Error object return by wp_insert_term() from foreach() loop in wp_set_object_terms()
|
|
Taxonomy
|
normal
|
defect (bug)
|
05/02/2018
|
4.7
|
needs-patch
|
|
#43900
|
Add hint about blocked Javascript as possible error reason in script-loader.php
|
|
Script Loader
|
normal
|
defect (bug)
|
05/02/2018
|
|
needs-patch
|
|
#43664
|
$wpdb->get_results fails in specific cases with non-latin charaters in where clause
|
|
Database
|
normal
|
defect (bug)
|
04/08/2018
|
4.9.4
|
needs-patch
|
|
#42512
|
Domain with special character redirect loop on homepage
|
|
Canonical
|
normal
|
defect (bug)
|
03/14/2018
|
4.5
|
needs-patch
|
|
#28297
|
Losing custom nav menu data while importing / exporting XML
|
|
Import
|
normal
|
defect (bug)
|
02/26/2018
|
3.9.1
|
needs-patch
|
|
#43025
|
wp_list_filter should filter all iterable objects
|
|
General
|
normal
|
defect (bug)
|
02/11/2018
|
4.9.1
|
needs-patch
|
|
#43033
|
User can not see updated Icon in editing Menu with live preview
|
|
Menus
|
normal
|
defect (bug)
|
02/05/2018
|
4.9.1
|
needs-patch
|
|
#19493
|
post and archive pagination don't work with custom endpoints
|
|
Rewrite Rules
|
normal
|
defect (bug)
|
01/25/2018
|
2.1
|
needs-patch
|
|
#23188
|
Hardcoded relative url 'async-upload.php' in plupload/handlers.js
|
|
Upload
|
normal
|
defect (bug)
|
01/18/2018
|
3.5
|
needs-patch
|
|
#40339
|
If $home_path=='wp' then WP::parse_request() will remove 'wp' from 'wp-json/wc/v1/products' in $pathinfo
|
|
Rewrite Rules
|
normal
|
defect (bug)
|
01/12/2018
|
4.7.3
|
needs-patch
|
|
#18842
|
wp_nav_menu confuses new developers when it falls through to page listing
|
|
Menus
|
normal
|
defect (bug)
|
09/20/2017
|
3.2
|
needs-patch
|
|
#34465
|
Uploader in Media Modal Not Working When Certain Library Arguments Present
|
|
Media
|
normal
|
defect (bug)
|
09/18/2017
|
4.0
|
needs-patch
|
|
#19896
|
Non-WP rewrites not saved on a multisite install
|
|
Rewrite Rules
|
normal
|
defect (bug)
|
08/22/2017
|
3.0
|
needs-patch
|
|
#32117
|
wp_get_attachment_metadata sizes array file misses path if using year/month organizing
|
|
Media
|
normal
|
defect (bug)
|
08/14/2017
|
4.2
|
needs-patch
|
|
#23483
|
Incorrect image URL for subsites when using UPLOADS constant on multisite subdirectory installation
|
|
Upload
|
normal
|
defect (bug)
|
07/08/2017
|
3.5.1
|
needs-patch
|
|
#39472
|
Code tag still parses embeds
|
|
Embeds
|
normal
|
defect (bug)
|
02/20/2017
|
4.7
|
needs-patch
|
|
#63900
|
Improve PHPDoc for wp_parse_id_list() in functions.php
|
|
General
|
normal
|
defect (bug)
|
08/31/2025
|
|
needs-docs
|
|
#60934
|
Internal Subnets are being blocked by wp_parse_url and why?
|
|
HTTP API
|
normal
|
defect (bug)
|
10/08/2024
|
|
needs-docs
|
|
#50260
|
Multisite - Getting actual user capabilities with get_role_caps() different with current_user_can()
|
|
Role/Capability
|
normal
|
defect (bug)
|
08/04/2023
|
5.4.1
|
needs-docs
|
|
#53208
|
WordPress editor documentation: a few suggested changes
|
|
Editor
|
normal
|
defect (bug)
|
05/14/2021
|
|
needs-docs
|
|
#65124
|
Please include additional data validation in class-IXR-server.php
|
|
General
|
normal
|
defect (bug)
|
05/15/2026
|
4.7
|
has-patch
|
|
#65153
|
Identify selected buttons (.active in button groups) in Windows High Contrast Mode
|
|
Administration
|
normal
|
defect (bug)
|
05/14/2026
|
|
has-patch
|
|
#65230
|
`redirect_canonical()` fails to redirect slug-based attachment URLs when `wp_attachment_pages_enabled` is disabled
|
|
Media
|
normal
|
defect (bug)
|
05/13/2026
|
6.4
|
has-patch
|
|
#65229
|
Remove WordPress.org IP from function documentation
|
|
HTTP API
|
trivial
|
defect (bug)
|
05/13/2026
|
|
has-patch
|
|
#62628
|
Server and client directive negation logic should align
|
|
Interactivity API
|
normal
|
defect (bug)
|
05/12/2026
|
6.5
|
has-patch
|
|
#65214
|
Refine the help text wording for backend editor
|
|
Help/About
|
normal
|
defect (bug)
|
05/11/2026
|
3.3
|
has-patch
|
|
#58223
|
Twenty Twenty: twentytwenty_get_post_meta needs global $has_meta
|
|
Bundled Theme
|
normal
|
defect (bug)
|
05/08/2026
|
|
has-patch
|
|
#53927
|
Add test for _get_cron_array()
|
|
Cron API
|
normal
|
defect (bug)
|
05/07/2026
|
|
has-patch
|
|
#54490
|
added test for get_num_queries and wp_get_nocache_headers
|
|
General
|
normal
|
defect (bug)
|
05/07/2026
|
|
has-patch
|
|
#56047
|
test for pre_option_{$option} filter
|
pbearne
|
Options, Meta APIs
|
normal
|
defect (bug)
|
05/07/2026
|
|
has-patch
|
|
#57081
|
test for wp_mkdir_p
|
|
General
|
normal
|
defect (bug)
|
05/07/2026
|
|
has-patch
|
|
#65161
|
Give an error message when a non-image is uploaded for site icon
|
|
Media
|
normal
|
defect (bug)
|
05/06/2026
|
|
has-patch
|
|
#65160
|
Misleading error message on user screen actions, if no role has been selected
|
|
Users
|
normal
|
defect (bug)
|
05/06/2026
|
|
has-patch
|
|
#28117
|
Admin bar shouldn't use dynamic styles on frontend for logged out visitors
|
|
Toolbar
|
normal
|
defect (bug)
|
05/06/2026
|
3.3
|
has-patch
|
|
#16858
|
Usage of HTTP_HOST in the administration
|
dd32
|
Administration
|
normal
|
defect (bug)
|
05/05/2026
|
3.1
|
has-patch
|
|
#52976
|
user emails comparison should be case insensitive
|
|
Users
|
normal
|
defect (bug)
|
05/03/2026
|
4.3
|
has-patch
|
|
#59354
|
Unnecessary queries performed when updating a post without providing categories or tags
|
|
Posts, Post Types
|
normal
|
defect (bug)
|
05/03/2026
|
|
has-patch
|
|
#65144
|
Passwords: trim() asymmetry between wp_hash_password() and wp_check_password() introduced in 6.8
|
|
General
|
normal
|
defect (bug)
|
05/03/2026
|
6.8
|
has-patch
|
|
#62950
|
PHP deprecation warning in /wp-admin/includes/class-automatic-upgrader-skin.php
|
|
Upgrade/Install
|
normal
|
defect (bug)
|
05/02/2026
|
6.7.2
|
has-patch
|
|
#64927
|
.media-upload-form .media-item min-height is causing a visual glitch
|
|
Media
|
normal
|
defect (bug)
|
04/30/2026
|
|
has-patch
|
|
#65048
|
wp_ajax_fetch_list(): Sanitize $_GET input before nonce construction
|
rajeshcp
|
Administration
|
normal
|
defect (bug)
|
04/23/2026
|
3.1
|
has-patch
|
|
#58751
|
Add noindex to 404 template
|
|
General
|
normal
|
defect (bug)
|
04/21/2026
|
|
has-patch
|
|
#9993
|
Rss and atom feeds are dropping some characters
|
|
Feeds
|
normal
|
defect (bug)
|
04/17/2026
|
2.7.1
|
has-patch
|
|
#64956
|
Unnecessary horizontal scrollbar on theme-editor.php in WordPress 7.0 RC1
|
|
General
|
normal
|
defect (bug)
|
04/17/2026
|
|
has-patch
|
|
#65082
|
WP_oEmbed()->fetch() uses wp_embed_defaults() incorrectly
|
|
Embeds
|
normal
|
defect (bug)
|
04/17/2026
|
|
has-patch
|
|
#20774
|
Flagging a user with any role on a subsite as spam leads to flagging the site as spam
|
|
Users
|
major
|
defect (bug)
|
04/16/2026
|
3.0
|
has-patch
|
|
#65076
|
Missing escaping in title tag
|
|
Login and Registration
|
normal
|
defect (bug)
|
04/15/2026
|
|
has-patch
|
|
#64929
|
Media edit screen shows file URL under “Permalink” for non-previewable formats
|
|
Media
|
normal
|
defect (bug)
|
04/14/2026
|
|
has-patch
|
|
#65072
|
Registering a query_var called 'preview_nonce' stops previews from working.
|
dsas
|
Query
|
normal
|
defect (bug)
|
04/14/2026
|
|
has-patch
|
|
#53417
|
The revisions endpoints provide an incorrect JSON schema
|
|
Revisions
|
normal
|
defect (bug)
|
04/14/2026
|
4.7
|
has-patch
|
|
#64926
|
REST API: GET requests fail object/array schema validation when params are JSON-serialized strings
|
|
REST API
|
normal
|
defect (bug)
|
04/14/2026
|
|
has-patch
|
|
#29051
|
get_raw_theme_root : Windows paths
|
|
Themes
|
critical
|
defect (bug)
|
04/13/2026
|
3.9.1
|
has-patch
|
|
#64760
|
Site Icon and Site Logo remove button styling inconsistent in Customizer
|
|
Customize
|
normal
|
defect (bug)
|
04/12/2026
|
|
has-patch
|
|
#62694
|
wpautop Misuse in the "widget_block_content" Filter with Shortcode Block
|
|
Widgets
|
normal
|
defect (bug)
|
04/09/2026
|
6.7.1
|
has-patch
|
|
#31689
|
Media player not working with 302 redirects
|
|
Media
|
normal
|
defect (bug)
|
04/09/2026
|
4.1.1
|
has-patch
|
|
#41314
|
If the required fields are not set on user profile's save, every field's value will be dropped
|
jackjohansson
|
Users
|
normal
|
defect (bug)
|
04/09/2026
|
4.8
|
has-patch
|
|
#59588
|
False returned instead of default value on get_option with failure of unserializing data.
|
|
Widgets
|
normal
|
defect (bug)
|
04/09/2026
|
6.3.2
|
has-patch
|
|
#61503
|
Hook parent_file
|
|
Administration
|
minor
|
defect (bug)
|
04/09/2026
|
6.5.5
|
has-patch
|
|
#63066
|
Warning when array passed to wp_check_invalid_utf8()
|
|
General
|
normal
|
defect (bug)
|
04/09/2026
|
6.7.2
|
has-patch
|
|
#38486
|
current_page_parent class wrongly added to menu item
|
williampatton
|
Menus
|
normal
|
defect (bug)
|
04/03/2026
|
4.6.1
|
has-patch
|