Elsas
MCP Security Status / WordPress Core

WordPress Core

advisory · 2 known security advisories in the elsas feed · worst severity HIGH KEV · last seen 2026-07-21.

→ Is your version of WordPress Core affected?
Send your dependency list or lockfile to check_affected on the MCP endpoint https://elsas.it/mcp — free when you're not affected, micro-priced (capped at $0.10) only on a confirmed match. Full remediation detail is in the paid get_today / get_items.

advisories

AdvisorySeverityCVSSAffected versionsFixed inDate
CVE-2026-60137HIGH KEVWordPress Core (all versions — see advisory)see advisory2026-07-21
CVE-2026-63030HIGH KEVWordPress Core (all versions — see advisory)see advisory2026-07-21
These are advisories on record in the elsas feed, each linked to its primary source (GHSA/CVE/OSV/CISA-KEV) — the authoritative record. This page is informational and is not a complete audit of WordPress Core.

verify

1. Open each linked advisory above — the primary source is the truth.
2. Each advisory was published in a daily report that is Ed25519-signed; see status.json for the report_id.
3. Full signature-verification recipe →