Skip to content

[GHSA-7653-r8cq-rf8w] The Nginx Cache Purge Preload plugin for WordPress is... #5845

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: hsntgm/advisory-improvement-5845
Choose a base branch
from

Conversation

hsntgm
Copy link

@hsntgm hsntgm commented Jul 23, 2025

Updates

  • Affected products
  • Source code location
  • Summary

Comments
I'm the maintainer of the affected WordPress plugin and have confirmed that psaux-it/nginx-fastcgi-cache-purge-and-preload is the correct GitHub repository for CVE-2025-6213. The vulnerability was responsibly disclosed by @cynau1t and fully patched in version 2.1.3 via advisory GHSA-636g-ww4c-2j54. This contribution adds the missing package metadata so GitHub can properly associate the advisory with the project and enable visibility for security tooling.

@github-actions github-actions bot changed the base branch from main to hsntgm/advisory-improvement-5845 July 23, 2025 03:58
@helixplant
Copy link

Hi @hsntgm,
Thank you for taking the time to supply us this data. This advisory did not receive broadcasting because it's not in one of the GitHub Advisory Database's supported ecosystems. I see you added the package under the Composer ecosystem as psaux-it/nginx-fastcgi-cache-purge-and-preload but I am unable to find it within the Packagist repository. Is there a package associated with the Nginx Cache Purge Preload plugin that can be found within one of the GitHub Advisory Database's supported ecosystems?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy