WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 21: One Click Makes a Rogue Admin, and Few Have a Recovery Plan
A critical Elementor flaw lets one clicked link create a rogue admin. Update to 4.3.2. Only 27.9% of WordPress pros have a hack recovery plan.
Latest WordPress articles
Browse all WordPress articlesIssue 21: One Click Makes a Rogue Admin, and Few Have a Recovery Plan
A critical Elementor flaw lets one clicked link create a rogue admin. Update to 4.3.2. Only 27.9% of WordPress pros have a hack recovery plan.
Gutenberg 24.1 Brings Matching Design Tools to Nearly Every Block
Gutenberg 24.1 adds background, color, and typography controls to almost every core block, plus a new text shadow panel in Global Styles.
Most WordPress Pros Still Have No Plan for Recovering From a Hack
Only 27.9% of WordPress pros have a breach recovery plan, a Melapress survey finds. Most learn of hacks when someone notices the site acting strangely.
A CSRF Flaw in Elementor Lets a Single Click Create a Rogue Admin Account
A critical flaw in Elementor, active on 10 million+ sites, lets one clicked link create a rogue admin account. Update to 4.3.2 now.
Issue 20: A Second Critical WordPress Patch, Under Attack Within a Day
WordPress 7.1.2 patches a critical, unauthenticated flaw already under active attack. A Tutor LMS bug and blockchain-hiding malware also demand attention.
WordPress Playground Can Now Show You What a Plugin's Emails Actually Look Like
WordPress Playground now lets you preview the emails a plugin or theme would send, so you can test contact forms and order confirmations before going live.