WordPress, explained for site owners.
WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.
Latest WordPress news roundup
Read the latest roundupIssue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
Latest WordPress articles
Browse all WordPress articlesAttackers Have Been Exploiting a Critical Super Forms Flaw Since July
Attackers have exploited a critical Super Forms plugin flaw since July, and Wordfence has blocked over 250,000 attempts. Update to 6.3.314 now.
Attackers Are Now Actively Exploiting That Critical Elementor Pro Flaw
Wordfence has blocked over 190,000 exploit attempts against the critical Elementor Pro file upload flaw. Update to 4.2.2 now if you haven't already.
Gutenberg 23.9 Makes It Easier to Insert Blocks and Spot Custom Styles
Gutenberg 23.9 adds an inserter shortcut to the block toolbar and dot indicators that flag blocks with custom style overrides.
WordPress Narrows What Counts as a Valid Security Bug Report
WordPress narrowed what counts as a valid bug bounty report after low-severity submissions became unmanageable. Core and Gutenberg rules are unchanged.
SQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover
A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.
Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In
A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.