Attackers Hit WordPress's Critical RCE Flaw Within 90 Minutes of the Patch

Attackers hit WordPress's critical RCE flaw within 90 minutes of the patch, and Patchstack logged over 65,000 attempts. Update to 7.0.2 now if you haven't.

WordPress's Worst Security Flaw in a Decade Was Found by AI in 10 Hours

A researcher used OpenAI's GPT-5.6 to find WordPress's worst unauthenticated flaw in years, for $25. If you haven't updated to 7.0.2, do it now.

WordPress 7.0.2 Fixes a Critical Flaw That Let Attackers Run Code on Your Site

WordPress 7.0.2 fixes a critical flaw that let anonymous attackers run code on unpatched sites. Confirm you're updated. Attacks are already happening.

Issue 10: 7.1 beta lands, and Mullenweg draws a line on AI in core

WordPress 7.1 Beta 1 brings responsive styling and a media overhaul, with final release set for August 19. WooCommerce adds a free Reddit Ads extension.

Issue 9: WordPress backs off, patches up, and counts the cost

WordPress 7.0.1 patches a registration spam hole and 31 other bugs. The Classic block stays after a reversed plan, and plugin sales data shows real strain.

Issue 7: Security patches, a classic exit, and a community loss

Update Ultimate Member now or attackers can reset admin passwords. Avada Builder also needs a patch. A 13-year backdoor hit 44 WordPress plugins.

Update Ultimate Member Now: Attackers Can Hijack Admin Accounts

Ultimate Member 2.11.4 and earlier lets contributor-level attackers reset admin passwords. Update to version 2.12.0 now.

Avada Builder has a critical file deletion flaw

Avada Builder users should update now. A patched flaw can let attackers delete server files without logging in.

Issue 6: Bad week for trusted updates

Trusted plugin updates spread malware this week. OptinMonster, TrustPulse, and ShapedPlugin Pro were all compromised. Check your admin accounts now.

Update Gravity SMTP now, attackers are targeting unpatched sites

Attackers are hitting a Gravity SMTP flaw that can expose email service keys, secrets, and login tokens.

ShapedPlugin Pro updates carried a backdoor

Attackers slipped a backdoor into ShapedPlugin Pro plugin updates sent through the official licensed channel.

Check for rogue admins if you use OptinMonster, TrustPulse, or PushEngage

A supply chain attack tampered with scripts from three marketing plugins and created hidden WordPress admin accounts.

Issue 5: Security got stricter

WordPress added a 24-hour delay before plugin auto-updates. UpdraftPlus patched a site takeover bug. Update now if you ever connected it to UpdraftCentral.

UpdraftPlus fixed a critical site takeover bug

If you use UpdraftPlus and connected it to UpdraftCentral, update now to close a critical admin takeover risk.

Issue 04: Patch now, watch 7.1

Three plugins have critical flaws under active attack. Burst Statistics, Everest Forms Pro, and Kirki all need updating before anything else this week.

Update Everest Forms Pro now, attackers are exploiting a critical bug

Attackers are exploiting a critical Everest Forms Pro bug that can let them take over unpatched WordPress sites.

Update Burst Statistics now, attackers are already using a site takeover flaw

Burst Statistics users should update to 3.4.2 now. Attackers are already exploiting a critical flaw that can take over a site.

Update Kirki now to stop an account takeover flaw

A Kirki plugin flaw could let attackers take over WordPress accounts, including admins. Update the plugin now.

Update WP Maps Pro now, this bug can hand over your site

A WP Maps Pro flaw lets attackers create admin accounts. If you use the plugin, update to 6.1.1 now.

Issue 3: Update now, lock it down

WordPress 7.0 had a strong first week. Most sites can update with confidence. WP Maps Pro has a critical flaw that lets attackers create admin accounts.

Issue 2: Test 7.0, patch checkout now

WordPress 7.0 is out. A critical FunnelKit flaw is stealing payment data from checkout pages. Recurring malware usually means a server breach.

Malware that keeps coming back may be a server breach, not a WordPress bug

If redirect malware returns after cleanup, your server may be compromised outside WordPress.

Critical FunnelKit flaw lets attackers steal WooCommerce payment data

Attackers actively exploit a FunnelKit flaw to inject payment skimmers into WooCommerce checkout pages.

Issue 1: 7.0 Gets Real

WordPress 7.0 is nearly out. Burst Statistics and Avada Builder both have critical flaws to patch now. The AI plugin for WordPress hits 1.0 this week.