WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
Latest WordPress articles
Browse all WordPress articlesCritical Flaw in GiveWP Lets Attackers Take Over Your Site Without Logging In
A CVSS 10 flaw in GiveWP lets attackers take over donation sites without logging in. Update to version 4.16.7.2 immediately.
Pods' Solo Developer Raced to Patch a Critical Flaw Across Six Plugin Versions
Pods shipped patches across six plugin versions after a critical flaw let attackers become admin. Its solo developer took the week off his job to fix it.
Your Store's Return Data Can Tell You Why Customers Send Items Back
Nearly 1 in 5 online orders gets returned. WooCommerce Analytics can show you why, and AutomateWoo can flag repeat offenders before they cost you more.
Issue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
WP Rocket's Post-Mortem: How a Known Bug Report Sat Ignored for Six Weeks
WP Rocket's post-mortem on last week's WordPress 7.1 outage reveals a bug report sat unassigned for six weeks. About 10% of its sites went down.
Critical Flaw in WPMU DEV Dashboard Lets Attackers Become Your Site Admin
A critical flaw in WPMU DEV Dashboard lets unauthenticated attackers become your site admin if Hub Single Sign-On is enabled. Update to 5.0.2 now.