Independent WordPress news for site owners

WordPress, explained for site owners.

WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.

Weekends
In your inbox
6 min
Read time
Free
No paywall

Latest WordPress articles

Browse all WordPress articles
September 22

Wordfence Found WordPress Malware That Hides on the Ethereum Blockchain

Wordfence found WordPress malware disguised as a must-use plugin that reinstalls itself and hides its control server inside the Ethereum blockchain.

Security
3 min
September 22

WordPress 7.1.2 Fixes a Critical Bug That Let Anyone Take Over Your Site

WordPress 7.1.2 fixes a critical, unauthenticated flaw that can let attackers run code on your site. It affects versions back to 2016. Update now.

Security
3 min
September 19

Click2Shell: The Full Story Behind the WordPress Theme Install Bug Patched This Week

A CSRF and selector injection chain called Click2Shell could let attackers run code by tricking an admin into clicking one link. Update to WordPress 7.1.1.

Security
3 min
September 19

WordPress 7.2 Roadmap: A Secrets API, Admin Re-Authentication, and the Ipsum Theme

WordPress 7.2 is set for December with a Secrets API, admin re-authentication for sensitive actions, and a new default theme called Ipsum.

WordPress Updates
3 min
September 18

A Critical Flaw in the Library That Opens iPhone Photos Could Expose Your Server

A critical flaw in libheif, the library servers use to process iPhone photos, can expose files or run code. Ask your host if it is patched.

Security
2 min
September 18

A High-Severity Flaw in Tutor LMS Lets Subscribers Take Over Your Server

A high-severity flaw in Tutor LMS lets any subscriber-level user take over your server. The plugin runs on 100,000+ sites. Update to 4.0.8 now.

Security
2 min