WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 15: Zero Logins Needed
Three unauthenticated plugin flaws hit Elementor Pro, Forminator, and User Profile Builder this week. WordPress 7.1 also launched with responsive styling.
Latest WordPress articles
Browse all WordPress articlesCritical Flaw in the Avada Theme Lets Attackers Take Over Your Site Without Logging In
A critical, unauthenticated flaw in the Avada theme and its Fusion Builder plugin lets attackers take over your site. Update to 7.16.1 now.
WordPress Wants to Stop Plugins From Storing Your API Keys as Plain Text
WordPress plans a Secrets API so plugins stop storing your API keys as plain text. It targets version 7.2, with the settings screen following in 7.3.
Critical Flaw in TranslatePress Lets Attackers Take Over Your Admin Account
An unauthenticated flaw in TranslatePress can hand attackers your admin's password reset link. It only triggers if a secondary language is active. Update now.
WordPress Playground Can Now Run Any Version Back to 2003
WordPress Playground can now boot any version back to 0.7 from 2003, right in your browser. Test old plugins or check compatibility before an upgrade.
WordPress Accessibility Team Previews Its First Official Plugin
WordPress's Accessibility Team previews a plugin that flags skipped heading levels and inaccessible blocks in real time. Not installable yet.
Two Critical Flaws in miniOrange SAML SSO Let Attackers Log In as Your Admin
Two critical flaws in the miniOrange SAML SSO plugin let attackers log in as your admin. Paid editions were missed by update checkers. Patch now.