Hi all, anyone know if this security issue and patch from WordPress would impact ClassicPress?
Versions of WordPress prior to 6.8 are not affected.
CP v2 was reforked from WP 6.3 if I am not mistaken - this means that this vulnerability should not be in CP IMHO (take this with a grain of salt - I might be wrong).
In any case that type of situation is the reason why we cherry pick regularly from WP. If this fix is something we need I am sure that it will be addressed during next core meeting on the Zulip.
To be on the safe side I am going to tag @MattyRob
The overview provided by WordPress indicates that ClassicPress (as a fork of WordPress 6.2.x) should not be affected. I have also had a quick review of the current ClassicPress code based and the vulnerable code prior to the patch is not the same.