
WordPress in the Media
233 mentions across press, blogs, and newsletters
July 2026
Class Action Against Automattic to Proceed After Judge Finds Company Tracked WP Engine Customers
After their proposed class action was dismissed in December, two agency owners have survived a second motion to dismiss thanks to the WordPress Engine Tracker website.
The WP Community Collective Rebrands as The WPOCC After WordPress Foundation Files Trademark Application for ‘WPCC’
New name, same mission. The WP Open Community Collective says it has rebranded to better reflect its intent to support open source contributors beyond WordPress.
A Guide to WordPress Web Design Agencies in 2026, When the Website Is the Cheap Part and the Maintenance Is the Business
A WordPress web design agency sells you a website. The website is the cheap part. What you actually sign is a subscription to keep a fragile thing upright – and the fragility is the product. A guide to what you're really renting.
WordPress 7.1 Beta 3 Now Available, Punts Unicode Email Support Over Security Concerns
Unicode email address support was merged into core six weeks ago after 11 years of development. It's been pulled from 7.1 and will move to a community plugin.
WordPress Playground Team Calls for Testers as New Dock-Based UI Aims to Fix Feature Discoverability
Playground has supported persistent sites since March, but users keep telling the team they don't know that. A new dock-based UI aims to fix the discoverability problem.
SQL injection isn't dead
The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it. Category: News
Matt Mullenweg Responds to Active Install Growth Data Ticket for First Time in Four Years, Cites “Competing Interests”
Four years after WordPress.org pulled the active install growth data for plugins, Matt Mullenweg has responded with a new reason for not bringing them back.
Security Researcher Used OpenAI’s Sol Ultra to Find WordPress’s Worst Vulnerability in Years
The full exploit chain abuses six internal WordPress mechanisms to go from anonymous visitor to admin in two HTTP requests.
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately t
GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25
GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced models could reshape vulnerability research. Researchers at Searchlight Cyber tasked GPT-5.6 Sol
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure,
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this v
Patch now: WordPress REST API bug allows remote code execution
<p class
Massive WordPress vulnerability requires no preconditions: hackers can run malicious code
Massive WordPress vulnerability requires no prec
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep resear
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A RES
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites g
WordPress 7.0.2 Patches Rare Pre-Authentication RCE as Hosts, CDNs Get 24-Hour Head Start
A private Slack channel, 24 hours' notice, and strict information-sharing rules. How the WordPress project coordinated industry-wide defenses before going public with vulnerabilities.
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
Overview On July 17, 2026, a GitHub Security Advisory was <a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42
WordPress Security Team Details 18 Months of GitHub Actions Hardening, Plans Org-Wide Enforcement
The Security Team has been tightening CI/CD workflows across WordPress's GitHub repos since January 2025. Here's what they've done, and what's next.
WordPress 7.1 Beta 1 Ships With Responsive Styling, Media Overhaul, and Persistent Toolbar
The WordPress 7.1 roadmap promised collaboration as a throughline. What's shipped in Beta 1 is a styling and media release — and it's solid.
Delaware Court Blocks CloudLinux From Launching AutopilotWP After Seahawk Alleges Competing Tool Was Built Using Its Trade Secrets
A Delaware court has halted CloudLinux's planned launch of AutopilotWP after Seahawk accused the company of using confidential business information to build a competing WordPress maintenance platform. CloudLinux says the lawsuit is "meritless."
Matt Mullenweg Vetoes Plan to Merge Knowledge Post Type and Guidelines in Core, Says AI Features Need Real-World Adoption First
WordPress co-founder says features should have impressive week-to-work growth before they land in core. A proposal for a new Knowledge post type and Guidelines feature didn't meet that bar.
WordPress just released a brand-new Apple TV app with thousands of free videos
It’s not every day that a new Apple TV app arrives for tvOS. WordPress just released WordPress TV, bringing vi
Australian businesses targeted in global content management system exploitation campaign
The ACSC reports that malicious actors are actively scanning websites for vulnerabilities in various CMS platforms and plugins, including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE.
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carrie
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now,
WordPress 7.0.1 Now Available, Fixes 31 Bugs
The first maintenance release for 7.0 fixes admin reskin issues, a CSS sanitization bug, and block editor regressions ahead of the 7.1 release.
Are Declining Plugin Sales the Canary in WordPress’ Coalmine?
Declining plugin sales are real, but they don't tell the whole story. In this op-ed, Matt Cromwell examines the forces reshaping the WordPress product market — from AI and search disruption to pricing and discoverability — and argues that the winners will be those willing to rethink long-held assump
WordPress 7.0 Ships with AI Foundations in Core, a Modernized Admin, and New Design Tools
WordPress 7.0, released on May 20, 2026, includes new AI infrastructure, a redesigned admin interface, and updated design tools. Key features comprise an AI Client, Abilities API,
WordPress Community Support Recorded a $372,000 Deficit in 2025 Even as Event Attendance Rose 27%
The WordPress Foundation's annual financials show a $722,000 swing in the event subsidiary's bottom line, and include an warning about WP Engine's legal action.
Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access
A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with WordPress plugins forming the primary attack surface. Cyber actors are scanning the internet for vulnerable sites and chaining unauthenticated file upload, remote cod
70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks
A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a growing security gap in the global web ecosystem, where millions of sites rely on aging
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in
WP Engine Opposes WordPress Foundation’s Trademark Bids in the U.S. and Canada, Alleging Fraud and Bad Faith
WP Engine argues the WordPress Foundation has never offered hosting services and filed the trademark applications to help Automattic extract license fees.
I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…
I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really Means Author: <a href="https://me
Android desktop mode made me miss my laptop in record time
Android desktop mode can turn a phone into a nearly usable workstation, but one workday with WordPress, browser tools, and a pile of accessories made the laptop look mercifully honest.
Host & Network Penetration Testing: Exploitation CTF 1 — eJPT (INE)
A walkthrough covering flatCore CMS exploitation, SSH brute-forcing, WordPress plugin enumeration, and unauthenticated file read to capture all four flags. Hello everyone!</
I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few…
I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few Weeks Late Author: Shi
WordPress Drops to 41.5% Market Share, but Three Datasets Tell Different Stories About What’s Going On
Three datasets, three stories — and a myriad of ways to unpack them. WordPress's market share decline is real, but the explanations dominating the conversation are simplistic. We decided to take a look.
How I stopped a massive WordPress spam attack with 4,700 lines of code in two days - thanks to Codex and Claude
Spam accounts overwhelmed my database. Claude found the weaknesses, Codex wrote the fixes, and I deployed a new defense.
June 2026
Taming WordPress: How I Cut Stack Costs With $1,632 Net Annual Savings While Achieving a 99 PageSpeed Score using Claude Code
For nearly twenty years, maintaining a high-traffic web presence has meant constantly outrunning the slow accumulation of digital debris. What starts as a series of quick feature trials and minor design tweaks inevitably hardens into systemic technical debt, burying application logic under layers of
Om Malik, One of WordPress’s Earliest Adopters and the Connector Behind Automattic, Has Died at 59
Om Malik was one of WordPress's earliest users and a pivotal connector in the project's formative years. In a tribute, Matt Mullenweg called him "my best friend and brother from another mother."
WordPress 7.1 Set to Hide Classic Block From the Inserter as Contributors Begin Phasing It Out
The Classic block won't be insertable in WordPress 7.1, and a full removal could follow as early as 7.2.
WordPress AI Team Proposes Adding Knowledge Post Type and Guidelines to Core
Core committer Greg Ziółkowski has published a merge proposal to bring a new wp_knowledge custom post type and the AI Team's Guidelines feature into WordPress core for 7.1.
Plugin Developers and Site Maintainers Push Back on WordPress.org’s 24-Hour Update Delay
The 24-hour cooldown blocks all updates, not just auto-updates, and plugin developers are asking for changes.
Survey: 60% of U.S. consumers dislike “AI” in brand messaging
WordPress VIP survey data shows “AI” labeling can hurt trust, while AI referrals rise. Marketers may need clearer attribution and more human tone.
WordPress plugin Gravity SMTP exploited for sensitive information disclosure
The vulnerability resides in an exposed REST API endpoint within the Gravity SMTP plugin.
Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks
A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1,
Developer Traces 13-Year Backdoor Campaign Across 44 WordPress.org Plugins to a Single Operator
The Plugins Team has confirmed the operation is even bigger than what Ginder discovered, with 56 plugins across 27 accounts — and that's only what the current team has tracked.
Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites
A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-
WordPress 7.1 Roadmap Focuses on Collaboration, Guidelines, and Responsive Styling With RTC Still Unresolved
Guidelines, responsive styling, and client-side media join a packed 7.1 roadmap, but how real-time collaboration shows up in core still TBC.
Law enforcement disrupts SocGholish botnet and Evil Corp servers
Authorities from the Netherlands, Canada, the United States, and Germany removed the SocGholish malware and backdoors from 14,971 compromised WordPress websites, also taking 106 servers and domains offline.
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]
Anne McCarthy Named WordPress 7.1 Release Lead
It's McCarthy's first time as release lead, with a packed WordPress 7.1 backlog and core committers questioning whether RTC belongs in core.
Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data
Threat actors are actively exploiting a critical security flaw in the widely used Gravity SMTP WordPress plugin to extract sensitive configuration data, including API keys and authentication tokens. The vulnerability, tracked as CVE-2026-4020 with a CVSS score of 5.3, affects all versions up to a
Hackers Actively Exploiting WordPress SMTP Plugin With 100,000+ Installs to Access Sensitive Data
Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites to harvest configuration data and live email credentials. The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity SMTP
AI bots hammered WordPress cart pages 3.75M times in a day, Kinsta data shows
Kinsta analyzed 10 billion requests and found AI bots trapped in query-string loops, hammering WooCommerce cart and checkout pages millions of times a day.
Core Committers Float Chrome-Style Canary Approach for WordPress, Question Whether RTC Belongs in Core
At WCEU, core committers discussed how to get more people testing WordPress and improving feedback loops, and floated some big ideas to get there.
The AI Search Race Is a Trust Problem
WordPress VIP’s survey shows marketers chasing AI referrals while consumers still click through to sources, distrust unattributed answers and punish visible AI messaging.
Hackers Inject Malicious JavaScript Into WordPress Sites to Deploy ErrTraffic ClickFix Lures
Hackers are injecting malicious JavaScript into compromised WordPress sites to deploy ErrTraffic-powered ClickFix lures, a campaign that achieved nearly 60% victim conversion rates an unprecedented figure in malware ecosystems. Threat actors exploit WordPress vulnerabilities to inject a single li
WordPress Plugins Team Adds Three Reviewers, Re-Opens Applications as Submissions Hit New Records
The WordPress Plugins Team just cleared a 1,050-plugin backlog while weekly submissions hit 700. Now it's looking for more reviewers before the next wave.
Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN supply-chain attack
Three popular plugins served malicious JavaScript through a compromised CDN.
Sixty percent of U.S. consumers say ‘AI’ in brand messaging is a turnoff, survey finds
WordPress VIP’s latest survey suggests consumers are wary of AI-generated answers even as companies increasingly view AI search as an important referral channel.
Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain
In April 2026, incident responders traced a sophisticated intrusion that abused compromised WordPress sites to deliver GULoader via an EtherHiding → ClickFix → UNC-chain. The real-world ClickFix incident produced convergent evidence from an ANY.RUN sandbox detonation and live EDR telemetry, revea
OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks
A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise. The campaign also affects the TrustPulse and PushEngage plugins, both developed by Awesome Motive, significantly amplifying the attack surface acr
Awesome Motive CDN Breach Hits 1.2 Million Sites Running OptinMonster
Attackers stole a CDN key from the OptinMonster website and used it to serve tampered JavaScript that created hidden admin accounts on WordPress sites.
OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack
A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec disc
Garofalo Details How AI Writes WordPress Social Content, Open Sources the Toolkit
From 3-4 posts a week to 3-4 requests a day across 11 platforms — and the AI-generated copy gets fewer complaints than when humans wrote it.
Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites
Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites
A supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious JavaScript into files distributed through official CDN infrastructure. The malware created hidden admini
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's con
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage. Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, and PushEngage, three plugins operated by Awesome Motive
‘Companies that can serve both human and agent audiences will be the ones that survive’: WordPress VIP CTO spells out the future of SEO, GEO and more
‘For decades, we’ve all built websites for Google’: WordPress VIP’s CTO argues that publishers must optimize websites for both human readers and AI agents, without forgetting about trust.
Formidable Forms: How to Build a WordPress Plugin That Automatically Assigns Sales Territories
Formidable Forms has built-in conditional logic, and it's genuinely good. You can show or hide fields, branch confirmation messages, and route email actions based on rules. We've had exceptional responses to sending a confirmation back to the dealers who submitted a demo request, with most of them u
Critical UpdraftPlus flaw puts 3 million WordPress sites at risk
<img alt="Critical UpdraftPlus flaw puts 3 million WordPress sites at risk" class="webfeedsFeaturedVisual wp-post-image" height="780" src="https://dataconomy.com/wp-content/uploads/2026/06/critical-updraftplus-flaw-puts-3-million-wordpress.jpg" style="display: block; margin: auto; margin-bottom: 10p
Kinsta adds free bot protection to all WordPress plans
Kinsta on June 9 launched Bot Protection for all plans, giving WordPress owners control over AI crawlers and automated traffic inside MyKinsta at no added cost.
CERN Moves the Birthplace of the Web to WordPress
A six-month CMS evaluation, more than 183,000 items of content, and 580 websites later, CERN's years-long WordPress migration is entering its final phase.
WordPress.org Launches ‘Protect the Shire’ Initiative, Adds 24-Hour Cooldown for Plugin and Theme Auto-Updates
Every release across WordPress.org's 78,000 plugins and themes now faces AI-powered review before auto-updates roll out — and a Wapuu named Gandalf is on the job.
WordCamp Europe Draws 2,458 to Kraków, Bouncing Back From Basel Dip as CERN Goes Live on WordPress
A 43% jump in ticket sales, CERN's flagship site going live on WordPress, and an eight-hour afterparty. Kraków delivered the WCEU the community wanted.
WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin
A popular WordPress plugin is once again being leveraged in website takeover attacks.
Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access
Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked. Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bounty program and earned $325 for it. W
Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites a
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]
Automated SEO: What It Is and How It Works in 2026
It cleans and filters the data, then builds an updated WordPress draft for each. It then emails me preview links. I skim the drafts, make sure all looks okay, then click one button (“Approve all”) and they go live, restamped … Read more ›
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution
Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites
Critical Everest Forms Pro RCE flaw exploited to create rogue WordPress admin accounts
Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code
Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, affects
In the AI era, is Shopify the new WordPress?
WordPress saw a generation of creators and Shopify has done something similar for commerce. Could there be parallels?
Gutenberg 23.3 Ships Experimental Customizable WordPress Dashboard
A drag-and-drop, widget-based dashboard has landed in the Gutenberg plugin as an experiment, and it's the admin's biggest structural shakeup in years.
Contributors Launch FSE-Style Outreach Program to Get Real-Time Collaboration Ready for WordPress 7.1
A new outreach program modeled on the FSE experiment wants early adopters testing collaborative editing across hosting environments before Beta 1 on July 15.
WordPress.org Overhauls 20-Year-Old Jobs Board, Adds Career Features to Profiles
WordPress.org's long-dormant jobs board has been redesigned with profile integration and an "open to work" toggle in the first major overhaul of the site in over a decade.
WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks
A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8
WP Engine bolts bot management onto Global Edge Security as AI crawlers surge
WordPress hosting company WP Engine Inc. today added bot management to its Global Edge Security service, giving site operators a way to filter the growing volume of automated and artificial intelligence traffic reaching their sites. The Austin, Texas-based company runs more than 5 million WordPre
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws
WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites
A critical security flaw in the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0 release. Tracked as CVE-2
Steam Community Profiles abused as C2 network in new WordPress malware infection campaign
A new cheeky malware campaign abuses the comment section as a roadsign to malware
Critical Kirki flaw exploited to hijack WordPress admin accounts
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]
Toolradar Research
See WordPress in context: The SaaS Press Index 2026
We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find WordPress's position relative to the 488 most-covered tools.
Read the reportExplore WordPress
Press coverage is one signal. See the full picture.