|
#65051
|
$_REQUEST['term'] used unsanitized in user search query
|
rajeshcp
|
Networks and Sites
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/16/2026
|
|
#20774
|
Flagging a user with any role on a subsite as spam leads to flagging the site as spam
|
|
Users
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/16/2026
|
|
#65064
|
Flaky test: test_get_theme_featured_list_api fails with external HTTP unavailability
|
|
Build/Test Tools
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/16/2026
|
|
#64956
|
Unnecessary horizontal scrollbar on theme-editor.php in WordPress 7.0 RC1
|
|
General
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/17/2026
|
|
#64917
|
WP 7.0 Connectors: unclear error message
|
|
AI
|
normal
|
normal
|
7.0.1
|
defect (bug)
|
has-patch
|
04/17/2026
|
|
#9993
|
Rss and atom feeds are dropping some characters
|
|
Feeds
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/17/2026
|
|
#65071
|
Focus border styling breaks slug input layout in Classic Editor
|
joedolson*
|
Editor
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/17/2026
|
|
#65055
|
_pad_term_counts() uses string-concatenated SQL without prepared statement
|
johnbillion
|
Taxonomy
|
normal
|
normal
|
7.1
|
enhancement
|
has-patch
|
04/17/2026
|
|
#63085
|
"Login details" spam sent by from the account registration page
|
|
Login and Registration
|
normal
|
normal
|
7.0.1
|
defect (bug)
|
has-patch
|
04/17/2026
|
|
#13822
|
Menu items that get unpublished still appear
|
nacin
|
Menus
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
04/18/2026
|
|
#64902
|
wp_save_image() fatal error when wp_save_image_file() returns WP_Error
|
|
Media
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/19/2026
|
|
#65101
|
Ensure layout classnames are applied to the inner blocks wrapper and not to its siblings
|
|
Editor
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65102
|
WP_MS_Users_List_Table::display_rows() should emit id="user-{ID}" on <tr> to match WP_Users_List_Table
|
|
Users
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#21912
|
Add return filter to current_theme_supports()
|
|
Themes
|
normal
|
normal
|
|
enhancement
|
has-patch
|
04/20/2026
|
|
#42517
|
get_file_data() doesn't support the single-line variant of post template headers
|
SergeyBiryukov
|
General
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#21650
|
replace serialize() with print_r() in stats() function in wp-includes/cache.php
|
|
Cache API
|
normal
|
normal
|
Future Release
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65014
|
Site Health: Error icon missing due to missing dashicons class
|
|
Site Health
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65046
|
get_weekstartend() has swapped variable names and comments for month and day
|
saratheonline
|
Date/Time
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65047
|
Missing escaping for XML error message
|
|
Pings/Trackbacks
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65083
|
Toolbar: Simplify profile item by removing "Howdy, <UserName>" text and using a circular avatar
|
audrasjb*
|
Toolbar
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/20/2026
|
|
#65098
|
get_site_icon_url() returns empty string even when fallback is defined, breaking wp-embed-site-icon in the_embed_site_title()
|
|
Embeds
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65048
|
wp_ajax_fetch_list(): Sanitize $_GET input before nonce construction
|
rajeshcp
|
Administration
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65052
|
Nonce check order flaw in post-quickdraft-save
|
rajeshcp
|
Security
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#65054
|
$_GET['pagenow'] and $_GET['widget'] unsanitized in dashboard AJAX handler
|
rajeshcp
|
Security
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#64950
|
wp_using_ext_object_cache can return null, causing type failures, potential fatals
|
westonruter
|
Cache API
|
normal
|
normal
|
7.1
|
defect (bug)
|
has-patch
|
04/20/2026
|
|
#63946
|
Introduce a mechanism for lazy-loading REST routes and handlers
|
|
REST API
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
has-patch
|
04/20/2026
|
|
#39687
|
Request headers sent incorrectly from `WP_Http` to `Requests`
|
|
HTTP API
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
01/27/2017
|
|
#33542
|
User preferences API idea
|
|
Users
|
normal
|
normal
|
Future Release
|
feature request
|
dev-feedback
|
02/05/2017
|
|
#31744
|
All PHP files in the root should be dummy files, pointing to wp-includes versions
|
|
Upgrade/Install
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
02/06/2017
|
|
#36564
|
Last Modified for Comments
|
|
Comments
|
normal
|
trivial
|
Future Release
|
enhancement
|
needs-unit-tests
|
02/12/2017
|
|
#32653
|
Improve Linkback Presentation
|
|
Pings/Trackbacks
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
02/14/2017
|
|
#34466
|
wp_register_form, wp_lost_password_form function
|
|
Login and Registration
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
02/22/2017
|
|
#40012
|
Only add_metadata if no matching value
|
|
Options, Meta APIs
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
03/02/2017
|
|
#38207
|
Disable Trackbacks by Default Keep Pingbacks On
|
|
Pings/Trackbacks
|
low
|
minor
|
Awaiting Review
|
enhancement
|
dev-feedback
|
03/07/2017
|
|
#40047
|
Add term_meta to WP_Term class getter method
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
03/13/2017
|
|
#34083
|
Feed for post type should link to post type archive if available
|
stevenkword
|
Feeds
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
03/17/2017
|
|
#17771
|
URL-encoded comment_author_url gets broken by MySQL varchar 200 length limit
|
SergeyBiryukov
|
Comments
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
03/18/2017
|
|
#40523
|
populate_options doesn't use correct add_options actions
|
|
Options, Meta APIs
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
05/02/2017
|
|
#29539
|
Plugin viewer not displaying video tutorials.
|
|
Plugins
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
05/05/2017
|
|
#26474
|
Add Filter to Username/Password Fields on Login Form?
|
|
Login and Registration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
05/13/2017
|
|
#28517
|
Logic error in WP_Rewrite flush_rules
|
|
Rewrite Rules
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
05/18/2017
|
|
#40835
|
Password and email change emails should not contain site-specific wording on multisite
|
|
Users
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
05/22/2017
|
|
#39883
|
Code hooking on `image_downsize` can no longer assume the file is an image
|
joemcgill
|
Media
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
05/23/2017
|
|
#39836
|
Display maximum file upload size on theme upload page
|
|
Themes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
06/25/2017
|
|
#41353
|
Async upload breaks when there are special characters into file name
|
|
Media
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
07/19/2017
|
|
#40676
|
wpautop adds opening & closing p tags around the opening a tag and around the closing a tag when the link contains certain flow content elements like div, h1, h2...
|
|
Formatting
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
needs-unit-tests
|
07/21/2017
|
|
#39158
|
Unify site deactivation process
|
|
Networks and Sites
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
08/14/2017
|
|
#41760
|
wp_list_comments callback params
|
|
Comments
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
08/31/2017
|
|
#41792
|
Suggested Enhancement to WordPress' Handling of Authors and Author URL's
|
|
Themes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
09/06/2017
|
|
#41791
|
Unicode + add_permastruct breaks rewrite rules
|
|
Rewrite Rules
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
needs-unit-tests
|
09/15/2017
|
|
#41746
|
oEmbed does not respect canonical provider url parameter
|
|
Embeds
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
needs-unit-tests
|
09/20/2017
|
|
#38276
|
"Is thing public/accessible" API
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
09/23/2017
|
|
#34316
|
User status inconsistent between single-site & multisite
|
|
Users
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
needs-unit-tests
|
09/27/2017
|
|
#39043
|
HTTP API :: Its Not Possible To Send Data In Body For GET Requests
|
rmccue
|
HTTP API
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
10/02/2017
|
|
#34798
|
Export Bug
|
|
Export
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
10/03/2017
|
|
#41544
|
$id_or_email parameter in get_avatar filter needs to be more concrete
|
|
Users
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
10/14/2017
|
|
#42218
|
General Settings: Description of Email address should be Email Address instead of just Address.
|
|
Administration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
10/16/2017
|
|
#40842
|
Adding template filters
|
|
Themes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
10/23/2017
|
|
#38265
|
Add term_relationship_id column to wp_term_relationships
|
|
Taxonomy
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
10/25/2017
|
|
#31093
|
Make $tag argument optional for has_shortcode()
|
|
Shortcodes
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
10/31/2017
|
|
#41819
|
Support the paged argument in WP_Site_Query and WP_Network_Query
|
spacedmonkey
|
Query
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
11/01/2017
|
|
#29795
|
Set JPEG quality for individual image_size
|
|
Media
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
11/10/2017
|
|
#23895
|
Max upload size 0 when post_max_size = 0
|
johnbillion
|
Upload
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
11/29/2017
|
|
#42058
|
Unit test for _autop_newline_preservation_helper()
|
|
Formatting
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
12/11/2017
|
|
#42879
|
Invent a “Recommended Tools” section
|
|
Administration
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
12/13/2017
|
|
#22435
|
Export API
|
|
Export
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
12/13/2017
|
|
#39958
|
Comment reply/cancel links work badly when comment form is above the comment list
|
|
Comments
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
01/15/2018
|
|
#43209
|
REST API should take settings errors into account
|
|
Options, Meta APIs
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
02/01/2018
|
|
#12718
|
Better structure for admin menu
|
|
Plugins
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
02/07/2018
|
|
#43663
|
Unit Test test_theme_file_uri_returns_valid_uri fails on directories with spaces
|
|
Build/Test Tools
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
03/30/2018
|
|
#43621
|
Introduce `add_action_once` and `add_filter_once` sugar.
|
|
Plugins
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
04/06/2018
|
|
#43210
|
Introduce singular capabilities for managing individual options
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
04/19/2018
|
|
#32642
|
Add supports argument to register_taxonomy
|
|
Taxonomy
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
04/30/2018
|
|
#42695
|
Text Widget: hard-coded width/height attributes are stripped from iframes
|
|
Widgets
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
05/02/2018
|
|
#40065
|
Check for invalid user before `lostpassword_post` in `retrieve_password()`
|
|
Login and Registration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
05/04/2018
|
|
#34927
|
user_url and user_email length too short
|
|
Users
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
05/14/2018
|
|
#36666
|
Enhance `remove_theme_support()` so that it can take additional arguments
|
|
Themes
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
05/15/2018
|
|
#44334
|
'Invalid username or email' can just be 'Invalid username' in retrieve_password function
|
|
Login and Registration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
06/08/2018
|
|
#44333
|
Password hint label needs to be re-worded and needs to have a minimum password length check
|
|
Login and Registration
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
06/08/2018
|
|
#43963
|
Add admin body class for multisite blog ID and network admin context
|
|
Administration
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
dev-feedback
|
06/26/2018
|
|
#42806
|
Allow installing themes in the Customizer on multisite
|
|
Customize
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
07/08/2018
|
|
#44595
|
wp_insert_post() inserts wrong GUID (adds http:// prefix)
|
|
General
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
07/17/2018
|
|
#44429
|
WP-CLI incompatibility with wp_redirect( https://... )
|
|
General
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
07/24/2018
|
|
#32639
|
A URL Agnostic Wordpress
|
|
General
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
07/25/2018
|
|
#44617
|
Introduce new 'hasBlock' behavior for TinyMCE 'BeforeSetContent' and 'SaveContent' events
|
|
Editor
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
07/26/2018
|
|
#44476
|
Backend section Access based on Role/User
|
|
Role/Capability
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
08/02/2018
|
|
#29030
|
Screen Options Poor Update/Rendering Causes Many things to Break
|
|
Administration
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
08/08/2018
|
|
#17916
|
Enqueued styles are only printed on login_footer in wp-login.php
|
|
Script Loader
|
normal
|
normal
|
Future Release
|
defect (bug)
|
dev-feedback
|
08/10/2018
|
|
#43844
|
PHP list language construct changed behaviour in PHP 7
|
SergeyBiryukov
|
Administration
|
normal
|
major
|
Awaiting Review
|
defect (bug)
|
dev-feedback
|
08/12/2018
|
|
#20947
|
feature request: one-click update for core, themes and plugins (all in one)
|
|
Upgrade/Install
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
08/13/2018
|
|
#43910
|
Add actions and filters so plugins can easily extend export/erasure functionality
|
|
Privacy
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
08/13/2018
|
|
#39418
|
Improve "Empty Spam" and "Empty Trash" user experience
|
|
Administration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
08/20/2018
|
|
#44906
|
Include greek accent characters on "remove_accents" function
|
|
Formatting
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
dev-feedback
|
09/13/2018
|
|
#18450
|
New safe action to add rewrite rules on
|
|
Rewrite Rules
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
09/21/2018
|
|
#37593
|
Replace "Super Admin" with "Network Administrator"
|
Mista-Flo
|
Administration
|
normal
|
normal
|
Future Release
|
enhancement
|
dev-feedback
|
09/24/2018
|
|
#44964
|
`redirect_guess_404_permalink` doesn't support array in `post_type` var
|
|
Query
|
normal
|
normal
|
Awaiting Review
|
defect (bug)
|
needs-unit-tests
|
10/01/2018
|
|
#45023
|
Improve parent and child category description example
|
|
Taxonomy
|
normal
|
minor
|
Awaiting Review
|
enhancement
|
dev-feedback
|
10/03/2018
|
|
#45313
|
Multisite site deletion email contains misleading language about user account
|
|
Administration
|
normal
|
normal
|
Awaiting Review
|
enhancement
|
dev-feedback
|
11/08/2018
|
|
#21256
|
New theme feature - add_theme_support( 'content-width', $defaults )
|
chriscct7
|
Themes
|
normal
|
normal
|
Awaiting Review
|
feature request
|
dev-feedback
|
11/22/2018
|
|
#45417
|
Lack of actions when wp_cache_flush is called
|
|
Cache API
|
normal
|
trivial
|
Future Release
|
enhancement
|
dev-feedback
|
12/02/2018
|