WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
Latest WordPress articles
Browse all WordPress articlesSQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover
A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.
Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In
A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.
Rank Math Pauses Its Support Agent Feature After Consent Backlash
Rank Math paused its Support Agent feature after users said it created login credentials without clear consent. It returns once consent flow is rebuilt.
WordPress Launches a Core Security Initiative to Keep Up With AI-Driven Bug Reports
WordPress is scaling its security team after bug reports jumped 15x, driven largely by AI-assisted research. Here's the new Core Security Initiative.
Rank Math's New 'Support Agent' Creates an Admin Password Without Asking First
Rank Math 1.0.277 reportedly creates an admin-level Application Password when you open Help and Support, without asking first. Revoke it now.
Critical Flaw in GiveWP Lets Attackers Take Over Your Site Without Logging In
A CVSS 10 flaw in GiveWP lets attackers take over donation sites without logging in. Update to version 4.16.7.2 immediately.