Independent WordPress news for site owners

WordPress, explained for site owners.

WPWithin explains what changed in WordPress, who needs to care, and what to do next. Read the weekly Weekend Within roundup or explore practical articles on security, AI, updates, and more.

Weekends
In your inbox
6 min
Read time
Free
No paywall

Latest WordPress articles

Browse all WordPress articles
September 03

Attackers Have Been Exploiting a Critical Super Forms Flaw Since July

Attackers have exploited a critical Super Forms plugin flaw since July, and Wordfence has blocked over 250,000 attempts. Update to 6.3.314 now.

Security
2 min
September 02

Attackers Are Now Actively Exploiting That Critical Elementor Pro Flaw

Wordfence has blocked over 190,000 exploit attempts against the critical Elementor Pro file upload flaw. Update to 4.2.2 now if you haven't already.

Security
2 min
September 02

Gutenberg 23.9 Makes It Easier to Insert Blocks and Spot Custom Styles

Gutenberg 23.9 adds an inserter shortcut to the block toolbar and dot indicators that flag blocks with custom style overrides.

Block Editor
2 min
September 02

WordPress Narrows What Counts as a Valid Security Bug Report

WordPress narrowed what counts as a valid bug bounty report after low-severity submissions became unmanageable. Core and Gutenberg rules are unchanged.

WordPress Updates
2 min
September 01

SQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover

A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.

Security
3 min
September 01

Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In

A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.

Security
3 min