A critical Elementor flaw is the one thing to fix today. Separately, a survey shows most WordPress professionals have no plan for recovering from a hack. Gutenberg, Playground, and the 7.2 schedule had quieter but useful news.
Security: Elementor’s One-Click Admin Takeover
Elementor 4.3.0 and 4.3.1 contain a CSRF flaw that let an attacker create a second administrator on your site. CSRF, or cross-site request forgery, means a link forces a logged-in user’s browser to do something they never chose.
Elementor’s Editor Events feature decided whether to skip its security check by looking for a specific text string in the URL. Anyone can add that string to a link. Patchstack says an administrator who clicks such a link ends up creating an attacker’s admin account without knowing it.
Elementor runs on more than 10 million sites. Update to 4.3.2 or later. If you installed Elementor while 4.3.0 or 4.3.1 was current, review your Users screen for accounts you don’t recognize.
The bug has a lot in common with Click2Shell, the WordPress core chain from earlier this month. Both depend on getting a busy administrator to click one link. Log out of wp-admin when you are done, and treat unexpected links with suspicion.
Security: Few Pros Have a Recovery Plan
That brings up a harder question: what do you do if a site is compromised? Only 27.9% of respondents to Melapress’s 2026 survey said they have a breach recovery plan. That is almost unchanged from last year’s 27%.
The most common way people learned of an incident, in 42.6% of cases, was that someone noticed the site acting strangely. Monitoring caught far fewer. Logs or alerts found 38.4%, and malware scanners found 30.1%.
Melapress sells an activity log plugin, so weigh the survey accordingly. The advice still holds up. Write down who restores the site, from which backup, and who tells your customers. Then test the backup. If malware keeps coming back after cleanup, the server itself may be breached, not WordPress.
Block Editor: Gutenberg 24.1 Evens Out the Design Tools
Gutenberg 24.1 arrived on September 30. Background, shadow, border, color, and typography controls now reach almost every core block. Before, a block might offer a background control but no border control.
Text shadow also gets its own panel in Global Styles, the place where you set design rules for the whole site. The Cover and Media & Text blocks now let you pick media from the sidebar. Gutenberg is a plugin that tests features before they reach WordPress core, so try it on a staging site first.
WordPress: Email Previews and a Livestreamed Release
WordPress Playground now has an Email tool. Playground is a free tool that runs a temporary WordPress site in your browser. The new tool shows every email a plugin or theme would send, with subject, sender, and a preview of the body. Use it to check a contact form or an order confirmation before you install anything on your live site.
On the schedule side, WordPress is also changing how releases are marked. Starting with 7.2 in December, the project is replacing in-person release parties with livestreamed webinars so the whole release squad can attend. The 7.2 roadmap already includes sudo mode, which asks for your password again before sensitive admin actions, and a Secrets API for storing credentials.
Real-time collaborative editing is not on the 7.2 roadmap. Anne McCarthy, who published the roadmap, wrote that more time is needed for architectural decisions and that leaving it off beats listing it and pulling it later.
End of article