The WordPress newsletter for site owners, every weekend.
Six minutes. The week's WordPress news translated, contextualised, and pushed back on when it deserves it. Free. Unsubscribe any time.
The latest issue
Shipped August 28, 2026Issue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
Past issues
The archiveIssue 15: Zero Logins Needed
Three unauthenticated plugin flaws hit Elementor Pro, Forminator, and User Profile Builder this week. WordPress 7.1 also launched with responsive styling.
Issue 14: When a PNG Isn't a PNG
WordPress 7.0.4 patches an Imagick RCE flaw, its third security release in weeks. Two plugin backdoors hit official update channels this week too.
Issue 13: A Backdoor Rode In Through the Front Door
WordPress 7.0.3 patches 12 flaws, one leading to remote code execution. A backdoored update hit Fluent Forms and Ninja Tables Pro for five hours.
Issue 12: WordPress's New Safety Net Just Passed Its First Real Test
A plugin backdoor never reached a single WordPress site, but WP2Shell attacks have topped 11 million attempts. WordPress 7.1 nears its August 19 release.
Issue 11: AI found WordPress's worst RCE in years, attackers followed in 90 minutes
Attackers hit WordPress's critical RCE within 90 minutes of the patch. An AI found the flaw in 10 hours. WordPress 7.1 drops a feature over security fears.
Issue 10: 7.1 beta lands, and Mullenweg draws a line on AI in core
WordPress 7.1 Beta 1 brings responsive styling and a media overhaul, with final release set for August 19. WooCommerce adds a free Reddit Ads extension.
Issue 9: WordPress backs off, patches up, and counts the cost
WordPress 7.0.1 patches a registration spam hole and 31 other bugs. The Classic block stays after a reversed plan, and plugin sales data shows real strain.
Issue 8: AI gets official access, a customs deadline, and Elementor's reset
The EU's customs exemption ended July 1, and shipments now get rejected for bad HS codes. Elementor just cut 30% of its staff to chase AI.
Issue 7: Security patches, a classic exit, and a community loss
Update Ultimate Member now or attackers can reset admin passwords. Avada Builder also needs a patch. A 13-year backdoor hit 44 WordPress plugins.
Issue 6: Bad week for trusted updates
Trusted plugin updates spread malware this week. OptinMonster, TrustPulse, and ShapedPlugin Pro were all compromised. Check your admin accounts now.
Issue 5: Security got stricter
WordPress added a 24-hour delay before plugin auto-updates. UpdraftPlus patched a site takeover bug. Update now if you ever connected it to UpdraftCentral.
Issue 04: Patch now, watch 7.1
Three plugins have critical flaws under active attack. Burst Statistics, Everest Forms Pro, and Kirki all need updating before anything else this week.
Issue 3: Update now, lock it down
WordPress 7.0 had a strong first week. Most sites can update with confidence. WP Maps Pro has a critical flaw that lets attackers create admin accounts.
Issue 2: Test 7.0, patch checkout now
WordPress 7.0 is out. A critical FunnelKit flaw is stealing payment data from checkout pages. Recurring malware usually means a server breach.
Issue 1: 7.0 Gets Real
WordPress 7.0 is nearly out. Burst Statistics and Avada Builder both have critical flaws to patch now. The AI plugin for WordPress hits 1.0 this week.