WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 19: No-Login Site Takeovers, and a New Look for WordPress's Default Theme
Two critical WordPress plugin flaws are being exploited with no login required. WordPress 7.1.1 patches 11 more bugs, and passkey login goes free.
Latest WordPress articles
Browse all WordPress articlesClick2Shell: The Full Story Behind the WordPress Theme Install Bug Patched This Week
A CSRF and selector injection chain called Click2Shell could let attackers run code by tricking an admin into clicking one link. Update to WordPress 7.1.1.
WordPress 7.2 Roadmap: A Secrets API, Admin Re-Authentication, and the Ipsum Theme
WordPress 7.2 is set for December with a Secrets API, admin re-authentication for sensitive actions, and a new default theme called Ipsum.
A Critical Flaw in the Library That Opens iPhone Photos Could Expose Your Server
A critical flaw in libheif, the library servers use to process iPhone photos, can expose files or run code. Ask your host if it is patched.
A High-Severity Flaw in Tutor LMS Lets Subscribers Take Over Your Server
A high-severity flaw in Tutor LMS lets any subscriber-level user take over your server. The plugin runs on 100,000+ sites. Update to 4.0.8 now.
Issue 19: No-Login Site Takeovers, and a New Look for WordPress's Default Theme
Two critical WordPress plugin flaws are being exploited with no login required. WordPress 7.1.1 patches 11 more bugs, and passkey login goes free.
WooCommerce Brings Back Its Purple Block Theme for Public Beta Testing
WooCommerce revived its shelved Purple block theme for public beta testing, with built-in galleries and headers extensions once required. Test on staging.