WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 15: Zero Logins Needed
Three unauthenticated plugin flaws hit Elementor Pro, Forminator, and User Profile Builder this week. WordPress 7.1 also launched with responsive styling.
Latest WordPress articles
Browse all WordPress articlesWP Rocket's Post-Mortem: How a Known Bug Report Sat Ignored for Six Weeks
WP Rocket's post-mortem on last week's WordPress 7.1 outage reveals a bug report sat unassigned for six weeks. About 10% of its sites went down.
Critical Flaw in WPMU DEV Dashboard Lets Attackers Become Your Site Admin
A critical flaw in WPMU DEV Dashboard lets unauthenticated attackers become your site admin if Hub Single Sign-On is enabled. Update to 5.0.2 now.
Critical Flaw in the Avada Theme Lets Attackers Take Over Your Site Without Logging In
A critical, unauthenticated flaw in the Avada theme and its Fusion Builder plugin lets attackers take over your site. Update to 7.16.1 now.
WordPress Wants to Stop Plugins From Storing Your API Keys as Plain Text
WordPress plans a Secrets API so plugins stop storing your API keys as plain text. It targets version 7.2, with the settings screen following in 7.3.
Critical Flaw in TranslatePress Lets Attackers Take Over Your Admin Account
An unauthenticated flaw in TranslatePress can hand attackers your admin's password reset link. It only triggers if a secondary language is active. Update now.
WordPress Playground Can Now Run Any Version Back to 2003
WordPress Playground can now boot any version back to 0.7 from 2003, right in your browser. Test old plugins or check compatibility before an upgrade.