Independent WordPress news for site owners

WordPress, explained for site owners.

WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.

Weekends
In your inbox
6 min
Read time
Free
No paywall

Latest WordPress articles

Browse all WordPress articles
September 01

SQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover

A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.

Security
3 min
September 01

Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In

A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.

Security
3 min
September 01

Rank Math Pauses Its Support Agent Feature After Consent Backlash

Rank Math paused its Support Agent feature after users said it created login credentials without clear consent. It returns once consent flow is rebuilt.

Security
2 min
September 01

WordPress Launches a Core Security Initiative to Keep Up With AI-Driven Bug Reports

WordPress is scaling its security team after bug reports jumped 15x, driven largely by AI-assisted research. Here's the new Core Security Initiative.

WordPress Updates
2 min
August 30

Rank Math's New 'Support Agent' Creates an Admin Password Without Asking First

Rank Math 1.0.277 reportedly creates an admin-level Application Password when you open Help and Support, without asking first. Revoke it now.

Security
3 min
August 29

Critical Flaw in GiveWP Lets Attackers Take Over Your Site Without Logging In

A CVSS 10 flaw in GiveWP lets attackers take over donation sites without logging in. Update to version 4.16.7.2 immediately.

Security
3 min