Skip to content
WordPress logo

WordPress in the Media

233 mentions across press, blogs, and newsletters

Top coverageTechCrunchTechRadarZDNetAhrefs Blog
1 major ·7 tech media

July 2026

therepository.email

Class Action Against Automattic to Proceed After Judge Finds Company Tracked WP Engine Customers

After their proposed class action was dismissed in December, two agency owners have survived a second motion to dismiss thanks to the WordPress Engine Tracker website.

Jul 28, 2026
therepository.email

The WP Community Collective Rebrands as The WPOCC After WordPress Foundation Files Trademark Application for ‘WPCC’

New name, same mission. The WP Open Community Collective says it has rebranded to better reflect its intent to support open source contributors beyond WordPress.

Jul 24, 2026
DNSK WORK

A Guide to WordPress Web Design Agencies in 2026, When the Website Is the Cheap Part and the Maintenance Is the Business

A WordPress web design agency sells you a website. The website is the cheap part. What you actually sign is a subscription to keep a fragile thing upright – and the fragility is the product. A guide to what you're really renting.

Jul 23, 2026
therepository.email

WordPress 7.1 Beta 3 Now Available, Punts Unicode Email Support Over Security Concerns

Unicode email address support was merged into core six weeks ago after 11 years of development. It's been pulled from 7.1 and will move to a community plugin.

Jul 23, 2026
therepository.email

WordPress Playground Team Calls for Testers as New Dock-Based UI Aims to Fix Feature Discoverability

Playground has supported persistent sites since March, but users keep telling the team they don't know that. A new dock-based UI aims to fix the discoverability problem.

Jul 23, 2026
aikido.dev

SQL injection isn't dead

The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it. Category: News

Jul 22, 2026
therepository.email

Matt Mullenweg Responds to Active Install Growth Data Ticket for First Time in Four Years, Cites “Competing Interests”

Four years after WordPress.org pulled the active install growth data for plugins, Matt Mullenweg has responded with a new reason for not bringing them back.

Jul 22, 2026
therepository.email

Security Researcher Used OpenAI’s Sol Ultra to Find WordPress’s Worst Vulnerability in Years

The full exploit chain abuses six internal WordPress mechanisms to go from anonymous visitor to admin in two HTTP requests.

Jul 21, 2026
darkreading

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

Jul 20, 2026
Cybersecurity News

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately t

Jul 20, 2026
Cybersecurity News

GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25

GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced models could reshape vulnerability research. Researchers at Searchlight Cyber tasked GPT-5.6 Sol

Jul 20, 2026
Tenable

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure,

Jul 20, 2026
GBHackers

GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE

A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this v

Jul 20, 2026
CSO Online

Patch now: WordPress REST API bug allows remote code execution

<p class

Jul 20, 2026
Cybernews

Massive WordPress vulnerability requires no preconditions: hackers can run malicious code

Massive WordPress vulnerability requires no prec

Jul 20, 2026
Help Net Security

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep resear

Jul 19, 2026
Help Net Security

Two new high severity WordPress vulnerabilities, patch immediately!

The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A RES

Jul 18, 2026
GBHackers

Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution

A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites g

Jul 18, 2026
therepository.email

WordPress 7.0.2 Patches Rare Pre-Authentication RCE as Hosts, CDNs Get 24-Hour Head Start

A private Slack channel, 24 hours' notice, and strict information-sharing rules. How the WordPress project coordinated industry-wide defenses before going public with vulnerabilities.

Jul 18, 2026
Cybersecurity News

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s

Jul 18, 2026
Rapid7 Blog

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Overview On July 17, 2026, a GitHub Security Advisory was <a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42

Jul 17, 2026
therepository.email

WordPress Security Team Details 18 Months of GitHub Actions Hardening, Plans Org-Wide Enforcement

The Security Team has been tightening CI/CD workflows across WordPress's GitHub repos since January 2025. Here's what they've done, and what's next.

Jul 17, 2026
therepository.email

WordPress 7.1 Beta 1 Ships With Responsive Styling, Media Overhaul, and Persistent Toolbar

The WordPress 7.1 roadmap promised collaboration as a throughline. What's shipped in Beta 1 is a styling and media release — and it's solid.

Jul 17, 2026
therepository.email

Delaware Court Blocks CloudLinux From Launching AutopilotWP After Seahawk Alleges Competing Tool Was Built Using Its Trade Secrets

A Delaware court has halted CloudLinux's planned launch of AutopilotWP after Seahawk accused the company of using confidential business information to build a competing WordPress maintenance platform. CloudLinux says the lawsuit is "meritless."

Jul 15, 2026
therepository.email

Matt Mullenweg Vetoes Plan to Merge Knowledge Post Type and Guidelines in Core, Says AI Features Need Real-World Adoption First

WordPress co-founder says features should have impressive week-to-work growth before they land in core. A proposal for a new Knowledge post type and Guidelines feature didn't meet that bar.

Jul 14, 2026
9to5Mac

WordPress just released a brand-new Apple TV app with thousands of free videos

It’s not every day that a new Apple TV app arrives for tvOS. WordPress just released WordPress TV, bringing vi

Jul 13, 2026
scworld.com

Australian businesses targeted in global content management system exploitation campaign

The ACSC reports that malicious actors are actively scanning websites for vulnerabilities in various CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.

Jul 13, 2026
Cybersecurity News

Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website

A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carrie

Jul 13, 2026
GBHackers

Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access

A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now,

Jul 13, 2026
therepository.email

WordPress 7.0.1 Now Available, Fixes 31 Bugs

The first maintenance release for 7.0 fixes admin reskin issues, a CSS sanitization bug, and block editor regressions ahead of the 7.1 release.

Jul 10, 2026
therepository.email

Are Declining Plugin Sales the Canary in WordPress’ Coalmine?

Declining plugin sales are real, but they don't tell the whole story. In this op-ed, Matt Cromwell examines the forces reshaping the WordPress product market — from AI and search disruption to pricing and discoverability — and argues that the winners will be those willing to rethink long-held assump

Jul 10, 2026
infoq.com

WordPress 7.0 Ships with AI Foundations in Core, a Modernized Admin, and New Design Tools

WordPress 7.0, released on May 20, 2026, includes new AI infrastructure, a redesigned admin interface, and updated design tools. Key features comprise an AI Client, Abilities API,

Jul 10, 2026
therepository.email

WordPress Community Support Recorded a $372,000 Deficit in 2025 Even as Event Attendance Rose 27%

The WordPress Foundation's annual financials show a $722,000 swing in the event subsidiary's bottom line, and include an warning about WP Engine's legal action.

Jul 10, 2026
GBHackers

Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access

A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with WordPress plugins forming the primary attack surface. Cyber actors are scanning the internet for vulnerable sites and chaining unauthenticated file upload, remote cod

Jul 9, 2026
Cybersecurity News

70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a growing security gap in the global web ecosystem, where millions of sites rely on aging

Jul 8, 2026
GBHackers

Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks

A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in

Jul 8, 2026
therepository.email

WP Engine Opposes WordPress Foundation’s Trademark Bids in the U.S. and Canada, Alleging Fraud and Bad Faith

WP Engine argues the WordPress Foundation has never offered hosting services and filed the trademark applications to help Automattic extract license fees.

Jul 7, 2026
infosecwriteups.com

I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…

I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really Means Author: <a href="https://me

Jul 5, 2026
DigitalTrends

Android desktop mode made me miss my laptop in record time

Android desktop mode can turn a phone into a nearly usable workstation, but one workday with WordPress, browser tools, and a pile of accessories made the laptop look mercifully honest.

Jul 4, 2026
infosecwriteups.com

Host & Network Penetration Testing: Exploitation CTF 1 — eJPT (INE)

A walkthrough covering flatCore CMS exploitation, SSH brute-forcing, WordPress plugin enumeration, and unauthenticated file read to capture all four flags. Hello everyone!</

Jul 3, 2026
infosecwriteups.com

I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few…

I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few Weeks Late Author: Shi

Jul 3, 2026
therepository.email

WordPress Drops to 41.5% Market Share, but Three Datasets Tell Different Stories About What’s Going On

Three datasets, three stories — and a myriad of ways to unpack them. WordPress's market share decline is real, but the explanations dominating the conversation are simplistic. We decided to take a look.

Jul 3, 2026
ZDNetTech Media

How I stopped a massive WordPress spam attack with 4,700 lines of code in two days - thanks to Codex and Claude

Spam accounts overwhelmed my database. Claude found the weaknesses, Codex wrote the fixes, and I deployed a new defense.

Jul 1, 2026

June 2026

Martech Zone

Taming WordPress: How I Cut Stack Costs With $1,632 Net Annual Savings While Achieving a 99 PageSpeed Score using Claude Code

For nearly twenty years, maintaining a high-traffic web presence has meant constantly outrunning the slow accumulation of digital debris. What starts as a series of quick feature trials and minor design tweaks inevitably hardens into systemic technical debt, burying application logic under layers of

Jun 26, 2026
therepository.email

Om Malik, One of WordPress’s Earliest Adopters and the Connector Behind Automattic, Has Died at 59

Om Malik was one of WordPress's earliest users and a pivotal connector in the project's formative years. In a tribute, Matt Mullenweg called him "my best friend and brother from another mother."

Jun 26, 2026
therepository.email

WordPress 7.1 Set to Hide Classic Block From the Inserter as Contributors Begin Phasing It Out

The Classic block won't be insertable in WordPress 7.1, and a full removal could follow as early as 7.2.

Jun 25, 2026
therepository.email

WordPress AI Team Proposes Adding Knowledge Post Type and Guidelines to Core

Core committer Greg Ziółkowski has published a merge proposal to bring a new wp_knowledge custom post type and the AI Team's Guidelines feature into WordPress core for 7.1.

Jun 24, 2026
therepository.email

Plugin Developers and Site Maintainers Push Back on WordPress.org’s 24-Hour Update Delay

The 24-hour cooldown blocks all updates, not just auto-updates, and plugin developers are asking for changes.

Jun 23, 2026
ContentGrip

Survey: 60% of U.S. consumers dislike “AI” in brand messaging

WordPress VIP survey data shows “AI” labeling can hurt trust, while AI referrals rise. Marketers may need clearer attribution and more human tone.

Jun 23, 2026
scworld.com

WordPress plugin Gravity SMTP exploited for sensitive information disclosure

The vulnerability resides in an exposed REST API endpoint within the Gravity SMTP plugin.

Jun 22, 2026
Cybersecurity News

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1,

Jun 19, 2026
therepository.email

Developer Traces 13-Year Backdoor Campaign Across 44 WordPress.org Plugins to a Single Operator

The Plugins Team has confirmed the operation is even bigger than what Ginder discovered, with 56 plugins across 27 accounts — and that's only what the current team has tracked.

Jun 19, 2026
GBHackers

Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites

A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-

Jun 19, 2026
therepository.email

WordPress 7.1 Roadmap Focuses on Collaboration, Guidelines, and Responsive Styling With RTC Still Unresolved

Guidelines, responsive styling, and client-side media join a packed 7.1 roadmap, but how real-time collaboration shows up in core still TBC.

Jun 19, 2026
scworld.com

Law enforcement disrupts SocGholish botnet and Evil Corp servers

Authorities from the Netherlands, Canada, the United States, and Germany removed the SocGholish malware and backdoors from 14,971 compromised WordPress websites, also taking 106 servers and domains offline.

Jun 18, 2026
BleepingComputer

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]

Jun 18, 2026
therepository.email

Anne McCarthy Named WordPress 7.1 Release Lead

It's McCarthy's first time as release lead, with a packed WordPress 7.1 backlog and core committers questioning whether RTC belongs in core.

Jun 18, 2026
GBHackers

Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data

Threat actors are actively exploiting a critical security flaw in the widely used Gravity SMTP WordPress plugin to extract sensitive configuration data, including API keys and authentication tokens. The vulnerability, tracked as CVE-2026-4020 with a CVSS score of 5.3, affects all versions up to a

Jun 18, 2026
Cybersecurity News

Hackers Actively Exploiting WordPress SMTP Plugin With 100,000+ Installs to Access Sensitive Data

Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites to harvest configuration data and live email credentials. The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity SMTP

Jun 18, 2026
PPC Land

AI bots hammered WordPress cart pages 3.75M times in a day, Kinsta data shows

Kinsta analyzed 10 billion requests and found AI bots trapped in query-string loops, hammering WooCommerce cart and checkout pages millions of times a day.

Jun 18, 2026
therepository.email

Core Committers Float Chrome-Style Canary Approach for WordPress, Question Whether RTC Belongs in Core

At WCEU, core committers discussed how to get more people testing WordPress and improving feedback loops, and floated some big ideas to get there.

Jun 18, 2026
Implicator

The AI Search Race Is a Trust Problem

WordPress VIP’s survey shows marketers chasing AI referrals while consumers still click through to sources, distrust unattributed answers and punish visible AI messaging.

Jun 17, 2026
GBHackers

Hackers Inject Malicious JavaScript Into WordPress Sites to Deploy ErrTraffic ClickFix Lures

Hackers are injecting malicious JavaScript into compromised WordPress sites to deploy ErrTraffic-powered ClickFix lures, a campaign that achieved nearly 60% victim conversion rates an unprecedented figure in malware ecosystems. Threat actors exploit WordPress vulnerabilities to inject a single li

Jun 17, 2026
therepository.email

WordPress Plugins Team Adds Three Reviewers, Re-Opens Applications as Submissions Hit New Records

The WordPress Plugins Team just cleared a 1,050-plugin backlog while weekly submissions hit 700. Now it's looking for more reviewers before the next wave.

Jun 17, 2026
TechRadarTech Media

Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN supply-chain attack

Three popular plugins served malicious JavaScript through a compromised CDN.

Jun 16, 2026
TechCrunchMajor Publication

Sixty percent of U.S. consumers say ‘AI’ in brand messaging is a turnoff, survey finds

WordPress VIP’s latest survey suggests consumers are wary of AI-generated answers even as companies increasingly view AI search as an important referral channel.

Jun 16, 2026
GBHackers

Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain

In April 2026, incident responders traced a sophisticated intrusion that abused compromised WordPress sites to deliver GULoader via an EtherHiding → ClickFix → UNC-chain. The real-world ClickFix incident produced convergent evidence from an ANY.RUN sandbox detonation and live EDR telemetry, revea

Jun 16, 2026
GBHackers

OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks

A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise. The campaign also affects the TrustPulse and PushEngage plugins, both developed by Awesome Motive, significantly amplifying the attack surface acr

Jun 16, 2026
therepository.email

Awesome Motive CDN Breach Hits 1.2 Million Sites Running OptinMonster

Attackers stole a CDN key from the OptinMonster website and used it to serve tampered JavaScript that created hidden admin accounts on WordPress sites.

Jun 16, 2026
Cybersecurity News

OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack

A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec disc

Jun 16, 2026
therepository.email

Garofalo Details How AI Writes WordPress Social Content, Open Sources the Toolkit

From 3-4 posts a week to 3-4 requests a day across 11 platforms — and the AI-generated copy gets fewer complaints than when humans wrote it.

Jun 16, 2026
Infosecurity Magazine

Attackers Hijack Popular WordPress Plugins to Deploy Backdoors

Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites

Jun 15, 2026
CyberInsider

Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites

A supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious JavaScript into files distributed through official CDN infrastructure. The malware created hidden admini

Jun 15, 2026
The Hacker News

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's con

Jun 15, 2026
Security Affairs

Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN

Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage. Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, and PushEngage, three plugins operated by Awesome Motive

Jun 15, 2026
TechRadarTech Media

‘Companies that can serve both human and agent audiences will be the ones that survive’: WordPress VIP CTO spells out the future of SEO, GEO and more

‘For decades, we’ve all built websites for Google’: WordPress VIP’s CTO argues that publishers must optimize websites for both human readers and AI agents, without forgetting about trust.

Jun 13, 2026
Martech Zone

Formidable Forms: How to Build a WordPress Plugin That Automatically Assigns Sales Territories

Formidable Forms has built-in conditional logic, and it's genuinely good. You can show or hide fields, branch confirmation messages, and route email actions based on rules. We've had exceptional responses to sending a confirmation back to the dealers who submitted a demo request, with most of them u

Jun 12, 2026
Dataconomy

Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

<img alt="Critical UpdraftPlus flaw puts 3 million WordPress sites at risk" class="webfeedsFeaturedVisual wp-post-image" height="780" src="https://dataconomy.com/wp-content/uploads/2026/06/critical-updraftplus-flaw-puts-3-million-wordpress.jpg" style="display: block; margin: auto; margin-bottom: 10p

Jun 11, 2026
PPC Land

Kinsta adds free bot protection to all WordPress plans

Kinsta on June 9 launched Bot Protection for all plans, giving WordPress owners control over AI crawlers and automated traffic inside MyKinsta at no added cost.

Jun 10, 2026
therepository.email

CERN Moves the Birthplace of the Web to WordPress

A six-month CMS evaluation, more than 183,000 items of content, and 580 websites later, CERN's years-long WordPress migration is entering its final phase.

Jun 10, 2026
therepository.email

WordPress.org Launches ‘Protect the Shire’ Initiative, Adds 24-Hour Cooldown for Plugin and Theme Auto-Updates

Every release across WordPress.org's 78,000 plugins and themes now faces AI-powered review before auto-updates roll out — and a Wapuu named Gandalf is on the job.

Jun 9, 2026
therepository.email

WordCamp Europe Draws 2,458 to Kraków, Bouncing Back From Basel Dip as CERN Goes Live on WordPress

A 43% jump in ticket sales, CERN's flagship site going live on WordPress, and an eight-hour afterparty. Kraków delivered the WCEU the community wanted.

Jun 9, 2026
TechRadarTech Media

WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin

A popular WordPress plugin is once again being leveraged in website takeover attacks.

Jun 9, 2026
Security Affairs

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked. Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bounty program and earned $325 for it. W

Jun 8, 2026
SecurityWeek

Everest Forms Vulnerability Exploited to Hack WordPress Sites

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites a

Jun 8, 2026
BleepingComputer

Critical Everest Forms Pro flaw exploited to take over WordPress sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]

Jun 6, 2026
Ahrefs BlogTech Media

Automated SEO: What It Is and How It Works in 2026

It cleans and filters the data, then builds an updated WordPress draft for each. It then emails me preview links. I skim the drafts, make sure all looks okay, then click one button (“Approve all”) and they go live, restamped … Read more &#8250

Jun 5, 2026
The Hacker News

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution

Jun 5, 2026
Infosecurity Magazine

Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites

Critical Everest Forms Pro RCE flaw exploited to create rogue WordPress admin accounts

Jun 4, 2026
Cybersecurity News

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, affects

Jun 4, 2026
TechRadarTech Media

In the AI era, is Shopify the new WordPress?

WordPress saw a generation of creators and Shopify has done something similar for commerce. Could there be parallels?

Jun 4, 2026
therepository.email

Gutenberg 23.3 Ships Experimental Customizable WordPress Dashboard

A drag-and-drop, widget-based dashboard has landed in the Gutenberg plugin as an experiment, and it's the admin's biggest structural shakeup in years.

Jun 4, 2026
therepository.email

Contributors Launch FSE-Style Outreach Program to Get Real-Time Collaboration Ready for WordPress 7.1

A new outreach program modeled on the FSE experiment wants early adopters testing collaborative editing across hosting environments before Beta 1 on July 15.

Jun 4, 2026
therepository.email

WordPress.org Overhauls 20-Year-Old Jobs Board, Adds Career Features to Profiles

WordPress.org's long-dormant jobs board has been redesigned with profile integration and an "open to work" toggle in the first major overhaul of the site in over a decade.

Jun 4, 2026
Cybersecurity News

WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks

A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8

Jun 3, 2026
SiliconAngle

WP Engine bolts bot management onto Global Edge Security as AI crawlers surge

WordPress hosting company WP Engine Inc. today added bot management to its Global Edge Security service, giving site operators a way to filter the growing volume of automated and artificial intelligence traffic reaching their sites. The Austin, Texas-based company runs more than 5 million WordPre

Jun 3, 2026
SecurityWeek

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws

Jun 3, 2026
GBHackers

WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites

A critical security flaw in the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0 release. Tracked as CVE-2

Jun 3, 2026
TechRadarTech Media

Steam Community Profiles abused as C2 network in new WordPress malware infection campaign

A new cheeky malware campaign abuses the comment section as a roadsign to malware

Jun 3, 2026
BleepingComputer

Critical Kirki flaw exploited to hijack WordPress admin accounts

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]

Jun 2, 2026

Toolradar Research

See WordPress in context: The SaaS Press Index 2026

We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find WordPress's position relative to the 488 most-covered tools.

Read the report

Explore WordPress

Press coverage is one signal. See the full picture.