<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>WPWithin</title><description>A smart, opinionated publication about WordPress for site owners. Plain English, every weekend.</description><link>https://wpwithin.com/</link><language>en</language><managingEditor>hello@wpwithin.com (WPWithin)</managingEditor><webMaster>hello@wpwithin.com (WPWithin)</webMaster><item><title>Issue 17: Five Critical Fixes and Two Flaws Under Attack</title><link>https://wpwithin.com/articles/weekly-17/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-17/</guid><description>Five plugins shipped critical fixes this week. Two older flaws are under attack, and Rank Math paused a feature that created credentials without consent.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>Governance</category><category>Block Editor</category><category>Business</category><category>AI</category></item><item><title>WordPress Is Replacing the Icons in Your Admin Bar and Menu</title><link>https://wpwithin.com/articles/wordpress-dashicons-svg-icons-admin/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-dashicons-svg-icons-admin/</guid><description>WordPress is replacing Dashicons with SVG icons in your admin bar and menu, fixing screen reader announcements and high-contrast display glitches.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>accessibility</category></item><item><title>Attackers Have Been Exploiting a Critical Super Forms Flaw Since July</title><link>https://wpwithin.com/articles/super-forms-file-upload-active-exploitation/</link><guid isPermaLink="true">https://wpwithin.com/articles/super-forms-file-upload-active-exploitation/</guid><description>Attackers have exploited a critical Super Forms plugin flaw since July, and Wordfence has blocked over 250,000 attempts. Update to 6.3.314 now.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Attackers Are Now Actively Exploiting That Critical Elementor Pro Flaw</title><link>https://wpwithin.com/articles/elementor-pro-active-exploitation-190000-attempts/</link><guid isPermaLink="true">https://wpwithin.com/articles/elementor-pro-active-exploitation-190000-attempts/</guid><description>Wordfence has blocked over 190,000 exploit attempts against the critical Elementor Pro file upload flaw. Update to 4.2.2 now if you haven&apos;t already.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Gutenberg 23.9 Makes It Easier to Insert Blocks and Spot Custom Styles</title><link>https://wpwithin.com/articles/gutenberg-23-9-inserter-style-overrides/</link><guid isPermaLink="true">https://wpwithin.com/articles/gutenberg-23-9-inserter-style-overrides/</guid><description>Gutenberg 23.9 adds an inserter shortcut to the block toolbar and dot indicators that flag blocks with custom style overrides.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>block-editor</category></item><item><title>WordPress Narrows What Counts as a Valid Security Bug Report</title><link>https://wpwithin.com/articles/wordpress-narrows-vulnerability-disclosure-scope/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-narrows-vulnerability-disclosure-scope/</guid><description>WordPress narrowed what counts as a valid bug bounty report after low-severity submissions became unmanageable. Core and Gutenberg rules are unchanged.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>SQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover</title><link>https://wpwithin.com/articles/all-in-one-wp-migration-sql-injection-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/all-in-one-wp-migration-sql-injection-vulnerability/</guid><description>A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In</title><link>https://wpwithin.com/articles/gravity-forms-arbitrary-file-upload-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/gravity-forms-arbitrary-file-upload-vulnerability/</guid><description>A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Rank Math Pauses Its Support Agent Feature After Consent Backlash</title><link>https://wpwithin.com/articles/rank-math-support-agent-paused/</link><guid isPermaLink="true">https://wpwithin.com/articles/rank-math-support-agent-paused/</guid><description>Rank Math paused its Support Agent feature after users said it created login credentials without clear consent. It returns once consent flow is rebuilt.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress Launches a Core Security Initiative to Keep Up With AI-Driven Bug Reports</title><link>https://wpwithin.com/articles/wordpress-core-security-initiative/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-core-security-initiative/</guid><description>WordPress is scaling its security team after bug reports jumped 15x, driven largely by AI-assisted research. Here&apos;s the new Core Security Initiative.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>Rank Math&apos;s New &apos;Support Agent&apos; Creates an Admin Password Without Asking First</title><link>https://wpwithin.com/articles/rank-math-support-agent-application-password-consent/</link><guid isPermaLink="true">https://wpwithin.com/articles/rank-math-support-agent-application-password-consent/</guid><description>Rank Math 1.0.277 reportedly creates an admin-level Application Password when you open Help and Support, without asking first. Revoke it now.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Critical Flaw in GiveWP Lets Attackers Take Over Your Site Without Logging In</title><link>https://wpwithin.com/articles/givewp-object-injection-rce-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/givewp-object-injection-rce-vulnerability/</guid><description>A CVSS 10 flaw in GiveWP lets attackers take over donation sites without logging in. Update to version 4.16.7.2 immediately.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>A New Plugin Turns Your WordPress Dashboard Into a Desktop</title><link>https://wpwithin.com/articles/openstation-desktop-mode-wp-admin-plugin/</link><guid isPermaLink="true">https://wpwithin.com/articles/openstation-desktop-mode-wp-admin-plugin/</guid><description>OpenStation lets you open wp-admin pages as draggable windows, like a desktop operating system. It&apos;s opt-in per user and fully reversible on deactivation.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>plugins</category></item><item><title>Pods&apos; Solo Developer Raced to Patch a Critical Flaw Across Six Plugin Versions</title><link>https://wpwithin.com/articles/pods-developer-emergency-patch-response/</link><guid isPermaLink="true">https://wpwithin.com/articles/pods-developer-emergency-patch-response/</guid><description>Pods shipped patches across six plugin versions after a critical flaw let attackers become admin. Its solo developer took the week off his job to fix it.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Your Store&apos;s Return Data Can Tell You Why Customers Send Items Back</title><link>https://wpwithin.com/articles/woocommerce-analytics-reduce-returns/</link><guid isPermaLink="true">https://wpwithin.com/articles/woocommerce-analytics-reduce-returns/</guid><description>Nearly 1 in 5 online orders gets returned. WooCommerce Analytics can show you why, and AutomateWoo can flag repeat offenders before they cost you more.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>commerce</category></item><item><title>Issue 16: Six Critical Flaws, One Perfect Score</title><link>https://wpwithin.com/articles/weekly-16/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-16/</guid><description>A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>Performance</category><category>Platform</category><category>AI</category></item><item><title>WP Rocket&apos;s Post-Mortem: How a Known Bug Report Sat Ignored for Six Weeks</title><link>https://wpwithin.com/articles/wp-rocket-wordpress-7-1-post-mortem/</link><guid isPermaLink="true">https://wpwithin.com/articles/wp-rocket-wordpress-7-1-post-mortem/</guid><description>WP Rocket&apos;s post-mortem on last week&apos;s WordPress 7.1 outage reveals a bug report sat unassigned for six weeks. About 10% of its sites went down.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>performance</category></item><item><title>Critical Flaw in WPMU DEV Dashboard Lets Attackers Become Your Site Admin</title><link>https://wpwithin.com/articles/wpmu-dev-dashboard-auth-bypass-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/wpmu-dev-dashboard-auth-bypass-vulnerability/</guid><description>A critical flaw in WPMU DEV Dashboard lets unauthenticated attackers become your site admin if Hub Single Sign-On is enabled. Update to 5.0.2 now.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Critical Flaw in the Avada Theme Lets Attackers Take Over Your Site Without Logging In</title><link>https://wpwithin.com/articles/avada-theme-fusion-builder-rce-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/avada-theme-fusion-builder-rce-vulnerability/</guid><description>A critical, unauthenticated flaw in the Avada theme and its Fusion Builder plugin lets attackers take over your site. Update to 7.16.1 now.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress Wants to Stop Plugins From Storing Your API Keys as Plain Text</title><link>https://wpwithin.com/articles/wordpress-secrets-api-proposal/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-secrets-api-proposal/</guid><description>WordPress plans a Secrets API so plugins stop storing your API keys as plain text. It targets version 7.2, with the settings screen following in 7.3.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>Critical Flaw in TranslatePress Lets Attackers Take Over Your Admin Account</title><link>https://wpwithin.com/articles/translatepress-account-takeover-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/translatepress-account-takeover-vulnerability/</guid><description>An unauthenticated flaw in TranslatePress can hand attackers your admin&apos;s password reset link. It only triggers if a secondary language is active. Update now.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress Playground Can Now Run Any Version Back to 2003</title><link>https://wpwithin.com/articles/wordpress-playground-legacy-versions/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-playground-legacy-versions/</guid><description>WordPress Playground can now boot any version back to 0.7 from 2003, right in your browser. Test old plugins or check compatibility before an upgrade.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>playground</category></item><item><title>WordPress Accessibility Team Previews Its First Official Plugin</title><link>https://wpwithin.com/articles/wordpress-accessibility-lab-plugin-prototype/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-accessibility-lab-plugin-prototype/</guid><description>WordPress&apos;s Accessibility Team previews a plugin that flags skipped heading levels and inaccessible blocks in real time. Not installable yet.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>accessibility</category></item><item><title>Two Critical Flaws in miniOrange SAML SSO Let Attackers Log In as Your Admin</title><link>https://wpwithin.com/articles/miniorange-saml-sso-auth-bypass-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/miniorange-saml-sso-auth-bypass-vulnerability/</guid><description>Two critical flaws in the miniOrange SAML SSO plugin let attackers log in as your admin. Paid editions were missed by update checkers. Patch now.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Critical Flaw in the Pods Plugin Lets Attackers Become Your Site Admin</title><link>https://wpwithin.com/articles/pods-plugin-privilege-escalation-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/pods-plugin-privilege-escalation-vulnerability/</guid><description>A critical flaw in the Pods plugin lets attackers become your site admin without logging in. Update to version 3.3.9.1 now if you run Pods.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Issue 15: Zero Logins Needed</title><link>https://wpwithin.com/articles/weekly-15/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-15/</guid><description>Three unauthenticated plugin flaws hit Elementor Pro, Forminator, and User Profile Builder this week. WordPress 7.1 also launched with responsive styling.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>WordPress Core</category><category>AI</category><category>Block Editor</category><category>Business</category></item><item><title>WP Rocket Sites Crashed After WordPress 7.1, Fix Now Live</title><link>https://wpwithin.com/articles/wp-rocket-wordpress-7-1-fatal-error/</link><guid isPermaLink="true">https://wpwithin.com/articles/wp-rocket-wordpress-7-1-fatal-error/</guid><description>WP Rocket sites crashed after WordPress 7.1 launched, taking down over a third of one host&apos;s fleet. Update to WP Rocket 3.23.2.2 to fix it.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><category>performance</category></item><item><title>Critical Flaw in Elementor Pro Lets Attackers Take Over Your Site Without Logging In</title><link>https://wpwithin.com/articles/elementor-pro-file-upload-rce-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/elementor-pro-file-upload-rce-vulnerability/</guid><description>An unauthenticated flaw in Elementor Pro lets attackers upload malicious files and take over your site. Update to version 4.2.2 now.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress 7.1 &apos;Mary Lou&apos; Is Here With Responsive Styling and a Rebuilt Image Editor</title><link>https://wpwithin.com/articles/wordpress-7-1-mary-lou-release/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-7-1-mary-lou-release/</guid><description>WordPress 7.1 is here with responsive design controls, a persistent admin bar, and a rebuilt image editor. Update now to get the new tools.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>Gutenberg 23.8 Lets You Link Straight to One Exact Post Revision</title><link>https://wpwithin.com/articles/gutenberg-23-8-shareable-revisions/</link><guid isPermaLink="true">https://wpwithin.com/articles/gutenberg-23-8-shareable-revisions/</guid><description>Gutenberg 23.8 lets editors link straight to one exact revision, emails you when someone mentions you in a note, and makes List View 40x faster.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>block-editor</category></item><item><title>WordPress&apos;s AI Plugin Can Now Translate Posts and Suggest Slugs</title><link>https://wpwithin.com/articles/wordpress-ai-plugin-1-3-0-translation-slugs/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-ai-plugin-1-3-0-translation-slugs/</guid><description>WordPress&apos;s AI plugin 1.3.0 adds in-editor content translation and slug suggestions. A key naming change also affects custom Abilities setups.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>wordpress-ai</category></item><item><title>Critical Flaw in Forminator Forms Lets Attackers Take Over Your Site Without Logging In</title><link>https://wpwithin.com/articles/forminator-forms-file-upload-vulnerability/</link><guid isPermaLink="true">https://wpwithin.com/articles/forminator-forms-file-upload-vulnerability/</guid><description>A critical flaw in Forminator Forms lets attackers upload malicious files and take over your site without logging in. Update to 1.56.2 now.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Critical Flaw in User Profile Builder Lets Attackers Log In as Your Admin</title><link>https://wpwithin.com/articles/user-profile-builder-auth-bypass/</link><guid isPermaLink="true">https://wpwithin.com/articles/user-profile-builder-auth-bypass/</guid><description>A critical flaw in User Profile Builder can let attackers log in as your site admin. Update to version 3.16.5 now if Automatic Log In is enabled.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Issue 14: When a PNG Isn&apos;t a PNG</title><link>https://wpwithin.com/articles/weekly-14/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-14/</guid><description>WordPress 7.0.4 patches an Imagick RCE flaw, its third security release in weeks. Two plugin backdoors hit official update channels this week too.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>Accessibility</category><category>Business</category></item><item><title>Study of 3,400 WordPress Plugin Reviews Finds Reliability, Not Missing Features, Drives 1-Star Ratings</title><link>https://wpwithin.com/articles/wordpress-plugin-reviews-reliability-study/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-plugin-reviews-reliability-study/</guid><description>A study of 3,400 WordPress.org plugin reviews found reliability failures drive 42% of 1-star ratings. Missing features caused just 2.5%.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>plugins</category></item><item><title>WordPress.org Launches an Official Browser Extension for Chrome and Safari</title><link>https://wpwithin.com/articles/wordpress-official-browser-extension/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-official-browser-extension/</guid><description>WordPress.org released an official browser extension for Chrome and Safari that hides your admin bar, adds shortcuts, and previews pages on mobile.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>WordPress 7.0.4 Fixes a Flaw That Let a Disguised Image Run Code on Your Server</title><link>https://wpwithin.com/articles/wordpress-7-0-4-security-release/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-7-0-4-security-release/</guid><description>WordPress 7.0.4 fixes a flaw where a disguised image upload lets an Author-level account run code on your server. Update now.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Matt Mullenweg Calls WordPress&apos;s Theme Accessibility Overhaul &apos;Permanently Delayed&apos;</title><link>https://wpwithin.com/articles/wordpress-accessibility-ready-theme-review-dispute/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-accessibility-ready-theme-review-dispute/</guid><description>Matt Mullenweg says a WordPress theme accessibility overhaul is permanently delayed, leaving theme authors unclear on a September delisting deadline</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>accessibility</category></item><item><title>Supply Chain Attack Hits Seven BdThemes Elementor Plugins With Hidden Backdoors</title><link>https://wpwithin.com/articles/bdthemes-elementor-plugins-supply-chain-backdoor/</link><guid isPermaLink="true">https://wpwithin.com/articles/bdthemes-elementor-plugins-supply-chain-backdoor/</guid><description>Attackers hijacked a promotional banner feed in seven BdThemes Elementor plugins to plant rogue admin accounts and hidden backdoors. Check your site now.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Issue 13: A Backdoor Rode In Through the Front Door</title><link>https://wpwithin.com/articles/weekly-13/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-13/</guid><description>WordPress 7.0.3 patches 12 flaws, one leading to remote code execution. A backdoored update hit Fluent Forms and Ninja Tables Pro for five hours.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>Block Editor</category><category>Commerce</category><category>Business</category></item><item><title>WordPress 7.0.3 Patches 12 Security Flaws, One Could Lead to Remote Code Execution</title><link>https://wpwithin.com/articles/wordpress-7-0-3-security-release/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-7-0-3-security-release/</guid><description>WordPress 7.0.3 fixes 12 security flaws, including a login screen bug that can lead to remote code execution. Update your site now.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress Security Reports Jumped From 30 a Month to 450 as AI Tools Take Over the Hunting</title><link>https://wpwithin.com/articles/wordpress-hackerone-450-reports-ai-security/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-hackerone-450-reports-ai-security/</guid><description>WordPress security reports jumped from about 30 a month to 450 in July, as AI tools like Anthropic and pwn.ai now find and prove exploitable bugs.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>A Forgotten Server Let Attackers Backdoor Fluent Forms Pro and Ninja Tables Pro Updates</title><link>https://wpwithin.com/articles/wpmanageninja-fluent-forms-ninja-tables-backdoor/</link><guid isPermaLink="true">https://wpwithin.com/articles/wpmanageninja-fluent-forms-ninja-tables-backdoor/</guid><description>A forgotten server let attackers backdoor Fluent Forms Pro and Ninja Tables Pro updates for five hours. Check your site if you updated on July 31.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>Patchstack: WordPress.org Holds Security Patches as Long as Cosmetic Updates</title><link>https://wpwithin.com/articles/patchstack-protect-the-shire-hold-times/</link><guid isPermaLink="true">https://wpwithin.com/articles/patchstack-protect-the-shire-hold-times/</guid><description>Patchstack found WordPress.org holds critical security patches for the same delay as cosmetic updates, leaving known flaws exposed for hours longer.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WooCommerce 11.0 Speeds Up Product Pages, Changes How Refunds Count in Reports</title><link>https://wpwithin.com/articles/woocommerce-11-0-release/</link><guid isPermaLink="true">https://wpwithin.com/articles/woocommerce-11-0-release/</guid><description>WooCommerce 11.0 speeds up product pages and checkout, fixes refund reporting by month, and lets guest buyers link past orders to a new account.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>commerce</category></item><item><title>WordPress 7.1 Lets You Style Button Hover and Focus Colors Without Code</title><link>https://wpwithin.com/articles/wordpress-71-button-hover-focus-states/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-71-button-hover-focus-states/</guid><description>WordPress 7.1 lets you set hover and focus colors on Button and Navigation Link blocks from Global Styles, no custom CSS needed.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>block-editor</category></item><item><title>WordPress 7.1 Release Candidate 1 Is Out, Final Release Still Set for August 19</title><link>https://wpwithin.com/articles/wordpress-71-rc1-release-candidate/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-71-rc1-release-candidate/</guid><description>WordPress 7.1 Release Candidate 1 is out, with the final release locked for August 19. Test it on a staging site before it reaches your dashboard.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>wordpress-updates</category></item><item><title>Critical Flaw in WooCommerce Social Login Lets Anyone Log In as Your Admin</title><link>https://wpwithin.com/articles/woocommerce-social-login-apple-jwt-auth-bypass/</link><guid isPermaLink="true">https://wpwithin.com/articles/woocommerce-social-login-apple-jwt-auth-bypass/</guid><description>A critical flaw in WooCommerce Social Login lets attackers log in as any user, including admins, by faking an Apple sign-in token. Update to 2.8.8 now.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>security</category></item><item><title>WordPress 7.1 Adds Tooltips to Explain Icon-Only Buttons in Your Admin Screens</title><link>https://wpwithin.com/articles/wordpress-71-admin-tooltips-toggletips/</link><guid isPermaLink="true">https://wpwithin.com/articles/wordpress-71-admin-tooltips-toggletips/</guid><description>WordPress 7.1 adds hover tooltips and an info button to icon-only admin controls, plus an explainer for the login screen&apos;s Remember Me checkbox.</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>accessibility</category></item><item><title>Issue 12: WordPress&apos;s New Safety Net Just Passed Its First Real Test</title><link>https://wpwithin.com/articles/weekly-12/</link><guid isPermaLink="true">https://wpwithin.com/articles/weekly-12/</guid><description>A plugin backdoor never reached a single WordPress site, but WP2Shell attacks have topped 11 million attempts. WordPress 7.1 nears its August 19 release.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>weekly-roundup</category><category>Security</category><category>Block Editor</category><category>Commerce</category><category>Community</category></item></channel></rss>