WPDigest.io

WPDigest 140

Digest 140: WordPress Emergency Patch  wp2shell RCE Under Active Attack

WordPress shipped emergency releases for a chained core vulnerability nicknamed “wp2shell” that let an anonymous attacker take over a default install with zero plugins  and within days, real-world exploitation was confirmed. Meanwhile, WooCommerce 11.0 reaches general availability today, WordPress 7.1 Beta 3 drops a long-awaited feature over security concerns, and a separate plugin flaw hit […]

Digest 140: WordPress Emergency Patch  wp2shell RCE Under Active Attack Read More »

Digest 139

Digest 139: WordPress Vulnerability Alert: Millions of Sites at Risk

This week in WordPress: a critical wake-up call. A 9.8-severity flaw in a popular OAuth SSO plugin just exposed millions of sites to full takeover, and two separate backdoor campaigns have compromised over a million installs. On the brighter side, WordPress 7.0.1 shipped with 31 fixes, WooCommerce 11.0 is on the way, and 7.1 Beta

Digest 139: WordPress Vulnerability Alert: Millions of Sites at Risk Read More »

Digest 138

Digest 138: WordPress Security Alert: 1.2M Sites Backdoored (2026) 

This week in WordPress, security takes center stage with multiple supply-chain incidents shaking the ecosystem. Alongside the latest WordPress 7.0 and WooCommerce updates, WordPress.org introduces new plugin review measures, while fresh data highlights why keeping your site updated has never been more important. Kinsta – The AI & Bot Traffic Reality CheckSmart WordPress pros are

Digest 138: WordPress Security Alert: 1.2M Sites Backdoored (2026)  Read More »

Digest 137

Digest 137: WordPress Is Under Attack  And 7.1 Is Fighting Back

SiteGround force-installed an AI plugin across 1 million sites without consent and walked away with a 1.1-star rating. Hackers are actively exploiting a Gravity SMTP flaw with 17 million attempts blocked so far, while a critical Avada Builder vulnerability (CVSS 9.1) puts another million sites at risk of full takeover. React 19 got pulled from

Digest 137: WordPress Is Under Attack  And 7.1 Is Fighting Back Read More »

Weekly Wordpress Digest 136

Digest 136: WordPress Under Attack: Security Crisis & Flaws 2026

WordPress’s market share has fallen for six consecutive months, now sitting at 41.90% as Shopify, Wix, and Squarespace continue to gain ground. Supply chain attacks remain front and center; the April Essential Plugin backdoor across 31 plugins prompted WordPress.org to institute a platform-wide 24-hour auto-update hold and launch the “Protect The Shire” security initiative. A

Digest 136: WordPress Under Attack: Security Crisis & Flaws 2026 Read More »

Digest 135

Digest 135: 150,000+ WordPress Sites at Risk? Plus WordPress 7.0 & AI Breakthroughs

WordCamp Europe closed in Kraków with 2,458 attendees, a live CERN keynote, and WordPress 7.0 as the throughline. Two actively exploited plugin flaws Kirki page builder and Burst Statistics need immediate patching; Patchstack’s 2026 report adds urgency with 11,334 new vulnerabilities in 2025 and a five-hour median exploit window. WooCommerce 10.8 ships review request emails,

Digest 135: 150,000+ WordPress Sites at Risk? Plus WordPress 7.0 & AI Breakthroughs Read More »

Digest 134

Digest 134: WordPress Market Share Is Fell From 43.2% to 41.9% Ahead of 7.0

This week, WordPress 7.0 “Armstrong” is finally out, and it reshapes the platform around native AI. This issue covers what actually shipped in 7.0, the new Connectors and Abilities APIs, the retirement of the PHP “beta” label, and a fresh wave of AI tooling. On the harder-news side, Matt Mullenweg published an emotional anniversary post

Digest 134: WordPress Market Share Is Fell From 43.2% to 41.9% Ahead of 7.0 Read More »

Digest 133

Digest 133: Divi 5 Arrives, WordPress 7.0 RC4 & Security Alerts

This week, the WordPress ecosystem is buzzing with major milestones and urgent security news. Elegant Themes has officially launched Divi 5, bringing a completely redesigned editing experience to one of the most popular page builders. Meanwhile, WordPress 7.0 marches closer to release with its fourth Release Candidate now available, and security researchers are sounding alarms

Digest 133: Divi 5 Arrives, WordPress 7.0 RC4 & Security Alerts Read More »

Digest-132

Digest 132: Automattic’s Link Fixer, & Official Claude Connector 🤖

This week, the WordPress ecosystem is moving fast—shifting focus from simple maintenance to deep AI integration and long-term web preservation. From Automattic’s new partnership to save the web from “link rot” to a major proposal to bring a provider-agnostic AI Client into the WordPress 7.0 Core, the future of the CMS is becoming smarter and

Digest 132: Automattic’s Link Fixer, & Official Claude Connector 🤖 Read More »