./www/php-ja-wordpress, Blogging tool written in php (Localized for Japanese)

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 7.0.3, Package name: php84-ja-wordpress-7.0.3, Maintainer: ryoon

WordPress is a state-of-the-art publishing platform with a focus on
aesthetics, web standards, and usability. WordPress is both free and
priceless at the same time.

This package is WordPress of Japanese localized version.
It has Japanese locale files and some extension/modifications for
website written in Japansese people, and for website located in Japan.


Required to run:
[www/php-curl] [graphics/php-gd] [archivers/php-zlib] [archivers/php-zip] [databases/php-mysqli] [www/php-fpm]

Required to build:
[pkgtools/cwrappers]

Package options: ap-php

Master sites:


Version history: (Expand)


CVS history: (Expand)


   2026-08-12 17:18:27 by Takahiro Kambe | Files touched by this commit (3) | Package updated
Log message:
www/php-ja-wordpress: update to 7.0.3

Prior to 7.0.3 release, please refer <https://ja.wordpress.org/news/> in
detail.

7.0.3 (2026-08-06)

Security updates

This release features several security fixes.  Because this is a security
release, it is recommended that you update your sites immediately.

The security team would like to thank the following people for responsibly
reporting vulnerabilities, and allowing them to be fixed in this release:

* A Contributor+ stored cross-site scripting (XSS) issue in the Post Date
  block reported by Alex Concha of the WordPress Security Team

* A Contributor+ stored cross-site scripting (XSS) issue in the Post Content
  block reported by n05ec

* An information disclosure issue in the Latest Comments block exposing
  comments on password-protected posts reported by Ehtisham Siddiqui of the
  WordPress Security Team

* A bypass of the email address confirmation flow reported by 0ways

* An Author+ CSS injection issue via a bypass of the safe CSS attribute
  filter reported by Anthropic

* A Contributor+ stored cross-site scripting (XSS) issue in posts via the
  emoji settings element reported by Asaf Mozes (amosec)

* A privilege escalation issue on multisite networks with user registration
  enabled, allowing a user to create a new site reported by Aikido Security

* A server-side request forgery (SSRF) issue in URL validation allowing
  requests to link-local ranges reported by Andrew Mohawk and multiple
  independent reporters

* A pre-auth reflected cross-site scripting (XSS) issue on the login screen
  with potential to lead to PHP code execution reported by the team at
  pwn.ai

* A disclosure of notes in comment feeds reported by Elio Gubser

* An enumeration of post slugs reported by HDWSec

* A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on
  sites with a large number of users reported by Naveen S and Ajmal
  Moochingal
   2026-07-18 14:44:59 by Takahiro Kambe | Files touched by this commit (2) | Package updated
Log message:
www/php-ja-wordpress: update to 6.9.5

6.9.5 (2026-7-17)

This is security release fixes these

* A facilitated SQL injection issue reported as a team by TF1T, dtro, and
  haongo.  (CVE-2026-60137 / GHSA-fpp7-x2x2-2mjf)

* A REST API batch-route confusion and SQL injection issue leading to Remote
  Code.  (CVE-2026-63030 / GHSA-ff9f-jf42-662q)
   2026-03-12 17:08:38 by Takahiro Kambe | Files touched by this commit (2) | Package updated
Log message:
www/php-ja-wordpress: update to 6.9.2

6.9.2 (2026-03-10)

This is a security release that features several fixes.

* A Blind SSRF issue reported by sibwtf, and subsequently by several other
  researchers while the fix was being worked on

* A PoP-chain weakness in the HTML API and Block Registry reported by Phat
  RiO

* A regex DoS weakness in numeric character references reported by Dennis
  Snell of the WordPress Security Team

* A stored XSS in nav menus reported by Phill Savage

* An AJAX query-attachments authorization bypass reported by Vitaly
  Simonovich

* A stored XSS via the data-wp-bind directive reported by kaminuma

* An XSS that allows overridding client-side templates in the admin area
  reported by Asaf Mozes

* A PclZip path traversal issue reported independently by Francesco Carlucci
  and kaminuma

* An authorization bypass on the Notes feature reported by kaminuma

* An XXE in the external getID3 library reported by Youssef Achtatal
   2026-03-11 16:19:45 by Takahiro Kambe | Files touched by this commit (2) | Package updated
Log message:
www/php-ja-wordpress: distfile change

Upstream changed distfile without changing its name.  It happened last year,
sigh.

Add DIST_SUBDIR and bump PKGREVISION since it contains some translation
updates.
   2026-03-08 14:46:07 by Takahiro Kambe | Files touched by this commit (3) | Package updated
Log message:
www/php-ja-wordpress: update to 6.9.1

pkgsrc change
* Allow php84 and php85.

WordPress 6.8.3 (2025-09-30)
WordPress 6.9 (2025-12-02)
WordPress 6.9.1 (2026-02-03)

* Changes from WordPress 6.8.2 are too many to write here, please refer
  <https://wordpress.org/news/category/releases/> in detail.
   2026-01-08 15:17:50 by Takahiro Kambe | Files touched by this commit (24)
Log message:
Remove reference to php81.
   2025-07-26 09:21:50 by Takahiro Kambe | Files touched by this commit (4) | Package updated
Log message:
www/php-ja-wordpress: update to 6.8.2

pkgsrc change: update PKG_OPTIONS

* Fix dependency in options.mk.
* Add php-fpm.
* Delete php-cgi since PHP CGI is always supported by base PHP language
  packages and it added redundant dependency.
* Remove PKG_OPTIONS_GROUP, PKG_OPTIONS of this package only adds dependency
  and not exclusive one.

WordPress 6.8.2 (2025-07-15)

Changes from WordPress 6.7.2 are too many to write here, please refer
<https://wordpress.org/news/category/releases/> in detail.

Japanese version specific changes are unknown.
   2025-02-24 16:07:36 by Takahiro Kambe | Files touched by this commit (2) | Package updated
Log message:
www/php-ja-wordpress: update to 6.7.2

6.7.2 (2025-02-11)

This release featuring 35 bug fixes.  For more information, please visit
<https://wordpress.org/documentation/wordpress-version/version-6-7-2/> in
detail.