Attackers Hit WordPress's Critical RCE Flaw Within 90 Minutes of the Patch
Attackers hit WordPress's critical RCE flaw within 90 minutes of the patch, and Patchstack logged over 65,000 attempts. Update to 7.0.2 now if you haven't.
WordPress's Worst Security Flaw in a Decade Was Found by AI in 10 Hours
A researcher used OpenAI's GPT-5.6 to find WordPress's worst unauthenticated flaw in years, for $25. If you haven't updated to 7.0.2, do it now.
WordPress 7.0.2 Fixes a Critical Flaw That Let Attackers Run Code on Your Site
WordPress 7.0.2 fixes a critical flaw that let anonymous attackers run code on unpatched sites. Confirm you're updated. Attacks are already happening.
Issue 10: 7.1 beta lands, and Mullenweg draws a line on AI in core
WordPress 7.1 Beta 1 brings responsive styling and a media overhaul, with final release set for August 19. WooCommerce adds a free Reddit Ads extension.
Issue 9: WordPress backs off, patches up, and counts the cost
WordPress 7.0.1 patches a registration spam hole and 31 other bugs. The Classic block stays after a reversed plan, and plugin sales data shows real strain.
Issue 7: Security patches, a classic exit, and a community loss
Update Ultimate Member now or attackers can reset admin passwords. Avada Builder also needs a patch. A 13-year backdoor hit 44 WordPress plugins.
Update Ultimate Member Now: Attackers Can Hijack Admin Accounts
Ultimate Member 2.11.4 and earlier lets contributor-level attackers reset admin passwords. Update to version 2.12.0 now.
Avada Builder has a critical file deletion flaw
Avada Builder users should update now. A patched flaw can let attackers delete server files without logging in.
Issue 6: Bad week for trusted updates
Trusted plugin updates spread malware this week. OptinMonster, TrustPulse, and ShapedPlugin Pro were all compromised. Check your admin accounts now.
Update Gravity SMTP now, attackers are targeting unpatched sites
Attackers are hitting a Gravity SMTP flaw that can expose email service keys, secrets, and login tokens.
ShapedPlugin Pro updates carried a backdoor
Attackers slipped a backdoor into ShapedPlugin Pro plugin updates sent through the official licensed channel.
Check for rogue admins if you use OptinMonster, TrustPulse, or PushEngage
A supply chain attack tampered with scripts from three marketing plugins and created hidden WordPress admin accounts.
Issue 5: Security got stricter
WordPress added a 24-hour delay before plugin auto-updates. UpdraftPlus patched a site takeover bug. Update now if you ever connected it to UpdraftCentral.
UpdraftPlus fixed a critical site takeover bug
If you use UpdraftPlus and connected it to UpdraftCentral, update now to close a critical admin takeover risk.
Issue 04: Patch now, watch 7.1
Three plugins have critical flaws under active attack. Burst Statistics, Everest Forms Pro, and Kirki all need updating before anything else this week.
Update Everest Forms Pro now, attackers are exploiting a critical bug
Attackers are exploiting a critical Everest Forms Pro bug that can let them take over unpatched WordPress sites.
Update Burst Statistics now, attackers are already using a site takeover flaw
Burst Statistics users should update to 3.4.2 now. Attackers are already exploiting a critical flaw that can take over a site.
Update Kirki now to stop an account takeover flaw
A Kirki plugin flaw could let attackers take over WordPress accounts, including admins. Update the plugin now.
Update WP Maps Pro now, this bug can hand over your site
A WP Maps Pro flaw lets attackers create admin accounts. If you use the plugin, update to 6.1.1 now.
Issue 3: Update now, lock it down
WordPress 7.0 had a strong first week. Most sites can update with confidence. WP Maps Pro has a critical flaw that lets attackers create admin accounts.
Issue 2: Test 7.0, patch checkout now
WordPress 7.0 is out. A critical FunnelKit flaw is stealing payment data from checkout pages. Recurring malware usually means a server breach.
Malware that keeps coming back may be a server breach, not a WordPress bug
If redirect malware returns after cleanup, your server may be compromised outside WordPress.
Critical FunnelKit flaw lets attackers steal WooCommerce payment data
Attackers actively exploit a FunnelKit flaw to inject payment skimmers into WooCommerce checkout pages.
Issue 1: 7.0 Gets Real
WordPress 7.0 is nearly out. Burst Statistics and Avada Builder both have critical flaws to patch now. The AI plugin for WordPress hits 1.0 this week.