14.5.2 addresses an “information disclosure” vulnerability via AJAX and oEmbed for “Activity” items.
Out of curiosity, was your source of public disclosure for CVE-2026-1360 via Wordfence and, if not, what was your source, if you don’t mind stating?
You already answered, I didn’t refresh the page before sending a reply.
@mike80222,
Are we done with this topic?
I guess so. I’m assuming there will be a 14.5.3 release soon, right?
There is something I’m confused about, regarding the wordfence notice, but I don’t know if I should go into that here.
Milestone 14.5.3 is up next and “soon” would be relative to the observer. All I can say is that the target date is set for August 29, 2026.
As for the Wordfence notice, I’m not at liberty to discuss in public. WordPress has an account on Slack, here is some information regarding such (there are numerous channels including those for BuddyPress and bbPress):
WordPress Chat
Join the WordPress community
Thanks @emaralive. We can definitely consider this topic closed.