
WordPress in the Media
382 mentions across press, blogs, and newsletters
October 2026
Automattic Applies for Closed .wordpress Domain in ICANN’s First Application Round Since 2012
The application pitches .wordpress as a space stewarded for the open web, but rules out registrations by anyone outside Automattic and its affiliates.
Mary Hubbard Calls on Hosting and Plugin Companies to Fund WordPress Security Program
Automattic has paid every WordPress bug bounty since 2017. Now, WordPress's executive director wants GoDaddy, Newfold Digital, and 30 other big companies in the ecosystem to chip in.
WordPress MCP Adapter Now Available as a Canonical Plugin on WordPress.org
The official WordPress MCP Adapter plugin already has over 40,000 active installs, less than a week after launching in the WordPress.org plugin directory.
WordPress Contributors Test New Server-Aware Approach for Real-Time Collaboration
After real-time collaboration was pulled from WordPress 7.0, contributors are testing a new approach where the server, not users' browsers, merges edits and tracks who made each one.
CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks
CyberXero has emerged as an initial access broker that combines familiar hacking tools with artificial intelligence to run large-scale intrusions. The Russian-speaking operator targeted WordPress and e-commerce sites worldwide while separately probing Ukrainian energy and utility organizations. T
WordPress libheif RCE: Exploit Chain
How a WordPress libheif RCE uses returned pixels to bypass ASLR, trigger a heap overflow and execute commands on exact Ubuntu and Debian stacks.
Critical WordPress Flaw Draws Exploit Attempts Within 5 Hours of Patch
Attackers began probing a critical WordPress vulnerability less than five hours after its security patch became available, according to WordPress security firm Patchstack and reports by Bleeping Computer.By the...
Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks
WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting, SQL injection, information disclosure, and other security weaknesses. The project recommends immediate updates, with fixes also available for older affected branches. Only the latest Wo
Weglot Disrupts Itself With an AI-Native Rebuild, Launches 2.0 on WordPress
Co-founder Rémy Berda's one-month experiment to build a fictional Weglot competitor from scratch ended with paying customers, and convinced the company it needed to rebuild from the ground up.
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that
Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads
A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially crafted HEIC image through the standard Media Library workflow. The issue, tracked as GHSA-x8r2-mggj-j6wr, affects the library’s uncompresse
Google Site Kit auto-tracks checkouts and form leads from 8 WordPress plugins
Version 1.187.0 lifted the Site Goals flag on September 7 across 5M+ active installs. Breakdowns start with no history, and the same events can feed Google Ads.
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to
WP Engine v. Automattic, Two Years On: Where the WordPress Drama Stands
WP Engine's lawsuit against Automattic turns two today. From a keynote and an 8% royalty demand to a jury trial that's a year away, here's where it stands and why it's far from over.
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler nam
WordPress Takes Its Turn Leading the Open Website Alliance as Mary Hubbard Eyes AI Regulation
WordPress Executive Director wants the coalition, which includes Drupal, Joomla!, and TYPO3, to build on its Cyber Resilience Act work and give open source a stronger voice as governments regulate AI.
Court Filings Reveal WordPress.org’s “Mission Control” Dashboard Tracked WP Engine’s ACF Pro Installs
A WordPress .org dashboard called "Mission Control" tracked installs of ACF Pro — a plugin the site doesn't host — and Matt Mullenweg raised an M&A "exit" before the WP Engine fight went public, according to newly public testimony.
WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor
A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore those removed. The investig
SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
A newly analyzed WordPress malware family, tracked as SC for the “SC_” markers embedded in its injected code, uses a self-healing persistence mesh that can restore a deleted backdoor within seconds. Researchers found that SC does not rely on a single web shell or plugin. Instead, the malware crea
September 2026
New Ecommerce Tools: September 30, 2026
New services this week include agentic commerce, product reviews, local businesses, returns management, WordPress development, and cross-border selling. The post New Ecommerce Tools: September 30, 2026 a
WordPress 7.2 Roadmap Includes New Security Features, Suggestion Mode for Notes, and Ipsum Default Theme
Collaborative editing has been deliberately left off the roadmap, and the December release will be livestreamed instead of launched during the State of the Word.
Automattic Purges Board After Failed Coup Against CEO Matt Mullenweg
Automattic, the company behind WordPress.com and open-source WordPress, purged its board after a failed coup attempt to oust CEO Matt Mullenweg. The move, driven by disagreements ov
WordPress Owner Automattic’s Board Reportedly Purged After Failed ‘Coup’ Against CEO
Automattic reportedly has new board members, advisers, and counsel after the old board failed to oust CEO Matt Mullenweg.
Cloudflare Details Its Migration from WordPress to EmDash
Cloudflare recently documented the migration of its main blog from WordPress to EmDash, the open source content management system developed internally. The new platfor
20i finds 88% of WordPress sites running outdated software as attacks rise
New analysis of 44 million sites shows outdated versions span all business sizes, with $391 billion in enterprise revenue exposed to unpatched flaws.
WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
WordPress administrators are being urged to patch a high-severity core vulnerability that can turn an anonymous comment into server-side command execution. Tracked as CVE-2026-93485 and demonstrated by the Comment2Shell proof-of-concept, the flaw is an unauthenticated stored cross-site scripting
Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code
The critical WordPress vulnerability CVE-2026-87902 is being actively exploited, with activity progressing from reconnaissance to attempts to write malicious PHP files on vulnerable servers. The flaw affects WordPress Core versions 4.7.0 through 7.1.1 and has been fixed in WordPress 7.1.2 and bac
Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites
A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised WordPress websites to deliver ClickFix lures disguised as Cloudflare Turnstile verification pages. Researchers at Sekoia assess with high confidence that the service is a copycat of the established ErrTraffic framework,
Fifth of News UK website traffic was ‘non-human’ in past six months
<img alt="(Left to right) Brian Alvey, chief technology officer at Wordpress VIP, Tom Jackson, chief technology officer at News UK, and Carly Steven, director of SEO and editorial e-commerce at Daily Mail, speaking at Press Gazette's Future of Media Technology Conference sitting in armchai
Update to WordPress 7.1.2 to fix a critical security flaw
WordPress has released an important update to address a serious security issue. The release of WordPress 7.1.2 fixes a critical unauthenticated path traversal vulnerability which is tracked as s CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical). Left unpatched, the flaw could allow an attac
WordPress 7.1.2 Patches Critical RCE Vulnerability, Attackers Begin Probing Within Hours
Attackers built probes from the patch diff and started scanning within hours of a fix for a critical WordPress core vulnerability that security engineer Robert Ressl first reported in July.
Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code
WordPress has released version 7.1.2 to address a critical path-traversal vulnerability, tracked as CVE-2026-87902, which could allow unauthenticated remote code execution (RCE) under specific server and theme configurations. This flaw carries a CVSS v4 score of 9.2 and affects WordPress versions
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker
Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In
WordPress has released version 7.1.2 to address a critical security vulnerability that could allow unauthenticated attackers to execute code on vulnerable websites under specific conditions. Site administrators should update immediately because successful exploitation may not require attackers to
WordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected
A newly identified WordPress malware strain is using a hidden plugin, stolen administrator access, and a blockchain-based command channel to remain active on compromised websites. The threat is built to survive common cleanup efforts while quietly collecting sensitive data from affected servers.
Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor Access
A newly analyzed WordPress malware implant combines must-use plugin persistence, hidden administrator accounts, credential theft, cross-site propagation, and Ethereum-based EtherHiding to create an unusually resilient backdoor. The malicious code masquerades as an automated health-check and repor
New Exvicy malware-as-a-service framework copies rival's code
Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's Threat Detection & Research team.
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixe
Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords
A suspected Chinese-speaking threat actor has used WordPress vulnerabilities to break into at least 49 organizations across 29 countries. The campaign exposed how a compromised website can become a launchpad for database theft, credential abuse, and wider network intrusion. The attackers exploite
Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites
A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged-in administrator to click a specially crafted link. WordPress version 7.1.1, released on September 17, 2026, addresses this issue. Research
Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link
WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-
Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617
Podcast Segment: Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet – SWN #617. Bacteria, Spartans Invade Athens, Agentic AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet, and More on this episode of the Security Weekly News.
Automattic names interim CFO after exec departures
Jeremy Klaperman, the CFO of the company's WordPress VIP Enterprise business unit, will act as CFO for the time being.
Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students. Tracked as CVE-2026-78175, t
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-a
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators. The activity reached more than 100,000 cust
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential
WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities
WordPress has released version 7.1.1, a security and maintenance update that fixes 11 vulnerabilities affecting the widely used content management system. Website owners and administrators are urged to install the update immediately to reduce the risk of cross-site scripting, authorization bypass
Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and Cl
Most WordPress pros still lack a breach recovery plan
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across t
WordPress 7.1.1 Ships 11 Security Fixes, Credits Anthropic and pwn.ai Again
More than 90 people contributed to WordPress 7.1.1, patching 11 vulnerabilities, including two reported by Anthropic and one by AI pentest firm pwn.ai.
Flaws in The Events Calendar WordPress plugin enable unauthenticated RCE
Both flaws can be exploited by leaving an anonymous comment on an event page.
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
The Bad Guy With An AI Named Claude
A lot of bad guys try to use Claude to do bad things. Mostly they fail. We think. Anthropic has disrupted a bunch of them, and offers an extensive report. If Anthropic is sharing the worst cases, or anything close … <a href="https://thezvi.wordpress.com/2026/09/15/the-bad-guy-with-an-ai-named-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects p
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns a routine file-upload feature into a direct path to server access. The vulnerability, tracked as CVE-
WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in
Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover
Two critical vulnerabilities in The Events Calendar WordPress plugin could allow unauthenticated attackers to take over vulnerable websites. The flaws affect more than 600,000 active installations. They can lead to remote code execution, administrator password resets, malware deployment, and full
4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
<s
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the di
Mullenweg’s Swift Return to Automattic Helm Exposes Boardroom Fractures at WordPress Parent
Matt Mullenweg reclaimed the CEO role at Automattic just two days after his board placed him on leave and installed the CFO as interim chief. The swift reversal, executed through in
Matt Mullenweg’s 48-Hour CEO Coup: How the WordPress Founder Reclaimed Automattic
Matt Mullenweg was placed on paid leave by Automattic's board on Sept. 9 after accusing directors of conspiracy. Two days later he declared himself back in control via Slack. The ra
WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reachin
Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?
<p class
WordPress.org Can Now Automatically Block High-Risk Plugin Updates Before They Ship
AI and Jetpack Scan now review every plugin release during the Protect the Shire cooldown window, with risky updates blocked before they reach users.
WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had previously lacked one. The move follows a real-world incident in which a backdoor was
Automattic CEO Matt Mullenweg 'forced' into leave of absence by WordPress parent company board
Mullenweg apparently forced out as CEO – we don't know when (or if) he will return.
WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in
Automattic Board Puts WordPress Co-Founder Matt Mullenweg on Paid Leave
Automattic's board voted on September 9 to put co-founder Matt Mullenweg on paid leave, installing finance chief Mark Davies as interim CEO. Mullenweg said he voted against it and got 50 minutes' notice. He still controls WordPress.org, which Automattic does not.
Automattic CEO Matt Mullenweg placed on leave
Matt Mullenweg, the CEO of WordPress.com owner Automattic, has been placed on a paid leave of absence, as reported earlier by 404 Media. In an internal message by the outlet, Mullenweg claims Automattic chief financial officer Mark Davies "conspired" with board members to place him on leave. "They v
ShopMy, Google and WordPress are among this year’s Digiday Technology Awards finalists
This year’s Digiday Technology Awards finalists reflect an industry adapting to a rapidly changing digital landscape, with AI-ready infrastructure, first-party data, privacy and operational efficiency emerging as defining priorities. Across publishing, commerce and advertising, technology lead
WordPress Under Siege: Critical Flaws in Popular Plugins Expose Millions to Takeover
Wordfence researchers uncovered critical unauthenticated file upload flaws in Elementor Pro and Super Forms affecting over six million WordPress sites. Both vulnerabilities, now pat
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to
SQL injection vulnerability in WordPress plugin affects millions of sites
The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.
Andy Peatling Left Automattic After 17 Years and Built Miles, an AI Design Agent for WordPress
He left Automattic thinking he was done with WordPress. Fourteen months later and after a lot of buzz, Andy Peatling has launched an AI design agent built entirely on native blocks.
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely us
WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks
A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7.110. The issue was re
WordPress Tightens Bug Bounty Scope After Monthly Security Reports Nearly Double to 773
Monthly reports to WordPress's HackerOne program have surged from a decade-long baseline of 20–30 to 773 in August, prompting the WordPress Security Team to change what it will accept.
Rank Math Pulls Controversial Support Agent as Matt Mullenweg Calls for Plugin Audits
The Rank Math plugin created admin-level passwords and sent them to group.one's servers before users accepted terms. Now, Matt Mullenweg wants mandatory audits for every plugin hosted on WordPress .org that phones home.
WordPress Is Using AI to Find Security Flaws Before Hackers Can Exploit Them
WordPress has launched a new security effort that uses artificial intelligence to identify vulnerabilities in its core software before attackers can abuse them. The initiative comes as the project receives an increasing number of security reports, driven in part by rapid improvements in AI tools
WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the world’s most widely used content management system. This initiative, known as the Core Security Initiative, responds to a significant
WordPress Announces Core Security Initiative as AI-Driven Vulnerability Reports Hit Record Levels
The WordPress project has formalized a core security effort in response to 15x spike in reports and an unprecedented period of core security releases.
August 2026
Enqueue Returns to Sydney to Explore What AI Means for WordPress Developers
Last year's debut drew 80 people and proved the concept. Now The Code Company is going it alone, with an AI-first program and a spot on the AI Week Sydney calendar.
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.
DMWF Spotlight: Enterprise teams spend 16.6 hours a week trying to get named by AI. Better writing isn’t what fixes it.
Marketing teams now spend over 16 hours a week on how their brand turns up in AI answers. That’s two working days every week according to WordPress VIP’s “Future of the Web 2026” report. Most teams have no idea what it buys them. What’s really happening Someone asks ChatGPT or G
Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the backgrou
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out
WordPress Signs Open Weights AI Letter Alongside Automattic and GoDaddy
More than 270 companies have asked US policymakers not to restrict open weight AI models. Automattic, GoDaddy, and now WordPress are among them.
Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data
A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the Philippine Navy. The intrusion shows how unpatched internet-facing systems can expose d
WP Rocket Publishes WordPress 7.1 Fatal Error Post-Mortem, Estimates 10% of Sites Were Hit
A July 6 GitHub report identified the bug that led to fatal errors and suggested a fix. A post mortem reveals WP Rocket reviewed it, couldn't reproduce it, and moved on.
Wordfence’s New AI Agent Chains Six Flaws Into a Critical Unauthenticated RCE in Popular Avada Theme
Wordfence launched an AI agent earlier this year that hunts wide. Now, it has one that hunts deep, and its first big find is a critical RCE in one of the most popular WordPress themes.
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all TranslatePre
WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks
A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. Tran
SaaS Isn’t Dead. Your UI Is.
Yesterday: I uploaded questions about some content for approval in Google Workspace. I never logged in. I updated Trello and found my new tasks. Without logging in. I updated landing pages and their forms in WordPress. I never logged in. I updated a disqualification picklist in our pipeline process
Playground Team Ships Legacy Version Support, Making 23 Years of WordPress History Available in the Browser
Playground can now boot any of 55 WordPress versions in seconds, no old PHP runtimes, database configs, and local server stacks required.
Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts
Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have been linked
Toolradar Research
See WordPress in context: The SaaS Press Index 2026
We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find WordPress's position relative to the 488 most-covered tools.
Read the reportExplore WordPress
Press coverage is one signal. See the full picture.