WordPress, without the developer-speak.
A smart, opinionated publication about what's actually happening in WordPress, written for WordPress site owners and for the developers and consultants who advise them.
This week's roundup
Read in fullIssue 04: Patch now, watch 7.1
Three urgent plugin updates, plus two WordPress 7.1 changes worth watching.
Recently
All articlesUpdraftPlus fixed a critical site takeover bug
If you use UpdraftPlus and connected it to UpdraftCentral, update now to close a critical admin takeover risk.
Issue 04: Patch now, watch 7.1
Three urgent plugin updates, plus two WordPress 7.1 changes worth watching.
Update Everest Forms Pro now, attackers are exploiting a critical bug
Attackers are exploiting a critical Everest Forms Pro bug that can let them take over unpatched WordPress sites.
Update Burst Statistics now, attackers are already using a site takeover flaw
Burst Statistics users should update to 3.4.2 now. Attackers are already exploiting a critical flaw that can take over a site.
Update Kirki now to stop an account takeover flaw
A Kirki plugin flaw could let attackers take over WordPress accounts, including admins. Update the plugin now.
Update WP Maps Pro now, this bug can hand over your site
A WP Maps Pro flaw lets attackers create admin accounts. If you use the plugin, update to 6.1.1 now.