Independent WordPress news for site owners

WordPress, explained for site owners.

WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.

Weekends
In your inbox
6 min
Read time
Free
No paywall

Latest WordPress articles

Browse all WordPress articles
September 25

A CSRF Flaw in Elementor Lets a Single Click Create a Rogue Admin Account

A critical flaw in Elementor, active on 10 million+ sites, lets one clicked link create a rogue admin account. Update to 4.3.2 now.

Security
3 min
September 25

Issue 20: A Second Critical WordPress Patch, Under Attack Within a Day

WordPress 7.1.2 patches a critical, unauthenticated flaw already under active attack. A Tutor LMS bug and blockchain-hiding malware also demand attention.

Weekend Within roundup
6 min
September 25

WordPress Playground Can Now Show You What a Plugin's Emails Actually Look Like

WordPress Playground now lets you preview the emails a plugin or theme would send, so you can test contact forms and order confirmations before going live.

Playground
3 min
September 23

Attackers Are Actively Exploiting the WordPress Flaw From Yesterday's Patch

Attackers are actively exploiting the critical WordPress flaw patched this week, writing files to servers that have not updated. Patch to 7.1.2 now.

Security
3 min
September 22

Wordfence Found WordPress Malware That Hides on the Ethereum Blockchain

Wordfence found WordPress malware disguised as a must-use plugin that reinstalls itself and hides its control server inside the Ethereum blockchain.

Security
3 min
September 22

WordPress 7.1.2 Fixes a Critical Bug That Let Anyone Take Over Your Site

WordPress 7.1.2 fixes a critical, unauthenticated flaw that can let attackers run code on your site. It affects versions back to 2016. Update now.

Security
3 min