WPDigest.io

Digest-118

Digest 118: Critical Admin Exploit & ACF Blocks V3

WPDigest Logo

This week a critical security warning for the Service Finder theme. Update immediately! We dive into product highlights, including the major release of ACF 6.6 with the improved ACF Blocks V3 editing UI, WP Rocket 3.20’s new Rocket Insights performance tool, and advanced query features in Bricks 2.1. Plus, find out about new Host Rep nominations, WPBakery’s loyalty pricing, and the upcoming FluentCart launch.


Kinsta_black

Kinsta â€“ The Future of WordPress Hosting is Here
Join the 120,000+ businesses who rely on Kinsta for secure, reliable WordPress hosting. Built entirely on Google Cloud, every plan offers advanced security, auto-scaling, and daily backups. We eliminate hosting headaches so you can focus on growth. It’s premium infrastructure, simplified.

See why 120k businesses trust Kinsta

SERPForge

SERP ForgeTransform Clicks into Customers
Outrank the competition with a proven strategy. SERP Forge provides the specialized SEO and content expertise needed to ensure your business doesn’t just rank, it dominates its niche. We optimize your visibility to capture high-value traffic and accelerate your conversion funnel.

Get the strategy you need to dominate


↑ Brought to you with support from these partners

đź’ˇ WordPress Spotlight

  • WordPress Hosting Team Opens Nominations for 2026 Team Reps
    The WordPress Hosting Team has launched its call for nominations for its 2026 Team Representatives. The administrative role requires roughly three hours per week for tasks like running chats and reporting updates. The team aims to elect 2-4 Reps for continuity and time zone coverage. Nominations close October 28, 2025, with the new reps starting in January 2026. (Source)
  • WPBakery Launches Loyalty Pricing with Growing Discounts
    WPBakery has introduced a new Loyalty Program for its Support Plus subscribers. Instead of front-loaded deals, the program rewards long-term customers by granting a 5% discount on the renewal fee for each consecutive year of active subscription. This discount increases annually up to a maximum of 50% off, in a move to reduce churn and reward customer commitment. (Source)
  • Critical Exploit Targets Service Finder Theme’s Authentication
    A critical authentication bypass exploit (CVE-2025-5947, CVSS 9.8) is actively targeting the Service Finder WordPress theme. The flaw, found in the bundled Service Finder Bookings plugin, allows unauthenticated attackers to hijack administrator accounts. Users must update the theme to version 6.1 immediately to patch this severe security risk. (Source)
  • Wordfence Reports Mass Exploitation of Service Finder Flaw
    Wordfence confirmed that attackers began exploiting the Service Finder Bookings plugin flaw (CVE-2025-5947) the day after disclosure (August 1, 2025). The firewall has blocked over 13,800 exploit attempts targeting this critical vulnerability, which allows unauthenticated admin access. Users are urgently advised to update to version 6.1. (Source)
  • WP Accessibility Day 2025 Announces Dates and Volunteer Call
    The annual WP Accessibility Day is scheduled for October 29-30, 2025, a free, 24-hour virtual event dedicated to WordPress accessibility. The organizing team is actively recruiting volunteers for 2025. Roles include accessibility testing, speaker outreach, and social media support. Get involved to help make this global, inclusive event a success. (Source)
  • WP Tavern Podcast on WP Accessibility Day Mission
    WP Tavern featured June Liu and David Denedo to discuss WP Accessibility Day. They highlight the event’s mission to drive practical change in web accessibility, powered by a large international volunteer team. The discussion covers the personal motivations of advocates and what attendees can expect from the free, 24-hour virtual event, including legal, technical, and design sessions. (Source)
  • Podcast Explores WordPress Use with Low Vision
    WP Tavern interviewed Bud Kraus, a legally blind educator, about teaching and using WordPress with macular degeneration. He discussed adapting his workflow with screen zoom, low resolution, and pattern recognition. His story emphasizes that accessibility requires empathy, not just technical compliance, and shows how his vision loss became a source of opportunity. (Source)
  • FluentAffiliate Exclusive Early Bird Lifetime Deal
    FluentAffiliate is currently offering an “Exclusive Early Bird Lifetime Deal,” which they state is the lowest price available. Pricing ranges from $199 for a 1-site license to $949 for a 50-site license. All plans include lifetime updates, support, and all features. (Source)
  • FluentCart Launching October 14, 2025
    WPManageNinja is preparing its “most ambitious project yet,” FluentCart, an e-commerce solution for WordPress. The plugin promises to change how users build and scale e-commerce sites without heavy server load or cost. The official LIVE launch is scheduled for October 14, 2025, at 6:30 AM (America/Los_Angeles). (Source)
  • WordCamp Asia 2026 Volunteer Applications Open
    Volunteer applications are officially open for WordCamp Asia 2026, set to take place in Mumbai, India, from April 9–11, 2026. Organizers are looking for accountable, effective, and trustworthy individuals. Selected volunteers will receive a complimentary ticket, a t-shirt, and swag in appreciation for their contribution to the global community. (Source)
  • Automattic’s Telex and the Future of Page Builders 
    A Pootlepress analysis suggests that Automattic’s experimental Telex project could render traditional page builders obsolete if it gains the ability to extend existing WordPress core blocks. Currently, Telex only creates new blocks, which can lead to technical debt. The author argues that allowing users to easily enhance core blocks (like adding advanced options to the Button block) would provide the flexibility users seek, leveraging WordPress’s solid foundation without fragmentation. (Source)
  • Anchor Host Experiments with Modernizing WordPress Core Code
    Anchor Hosting’s Austin Ginder detailed “Code Mapping,” the second part of his WordPress modernization experiment. Using the Minnow Transmuter script, he is mapping WordPress’s old, anonymous PHP functions into organized namespaces, aiming to create a cleaner, modern codebase (conceptualized as Minnow Bridge). The long-term goal is to separate the core code to potentially enable the use of WordPress plugins (like Gravity Forms) outside of a full WordPress installation. (Source)
  • WooCommerce 10.3 Introduces Experimental Session Cleanup
    WooCommerce 10.3 includes an experimental feature to automatically clear empty customer sessions for non-logged-in users. This change is designed to improve site performance and cache compatibility by removing unnecessary session cookies that prevent effective page caching. Developers are advised to test this feature and update their extensions to use alternative cache-bypassing methods if they currently rely on setting an empty session cookie. (Source)
  • WooCommerce 10.3 Experimental Session Cleanup
    WooCommerce 10.3 adds an experimental feature to automatically clear empty customer sessions for guests. This is designed to boost site performance and cache compatibility by removing unnecessary session cookies. Developers must test the change and use alternative methods if their extensions rely on setting an empty session cookie for cache bypassing. (Source)
  • The WP World Launches Real-Time Multilingual Chat
    The WP World launched a new feature that enables real-time multilingual chat among its users (“Pressers”), powered by OpenAI translation. Users can now send and receive messages in their own language, supporting over 130 languages and dialects. This enhancement aims to improve cross-border connectivity and make the global WordPress community more inclusive. (Source)
  • How WordPress Became a Web Giant | Automattic Founder and CEO Matt Mullenweg
    Automattic CEO Matt Mullenweg discusses the “Grit” required for founder longevity, noting WordPress powers 43% of the web. He shares his first major controversy in 2005 and his current, draining legal battle with a private equity-backed company over open-source trademarks. Mullenweg maintains that his enduring passion for the open web and democratizing publishing is his life’s mission. (Source)
  • WordPress 6.9, Mega Menus, and FSE Adoption
    The Gutenberg Times highlights calls for testing WordPress 6.9 features, including the Accordion Block and template management changes. Developers are reviewing the Ollie’s Menu Designer plugin for potential inclusion into core to provide native Mega Menus. The edition also features a case study on successfully migrating a site from Elementor to the Full Site Editor. (Source)
  • 10Web’s Vibe: AI-Powered Frontend Builder
    10Web is launching Vibe for WordPress, which they claim is the world’s first AI-Powered Vibe Coding frontend builder fully integrated with the WordPress backend. “Vibe coding” allows users to generate complex frontend designs, custom layouts, and animations using simple, descriptive prompts (natural language). The tool is built on a modern stack (React + Tailwind), features instant deployment, and generates 100% open-source code. It is positioned as the next evolution, replacing traditional drag-and-drop editors. (Source)
  • Kinsta Appoints New CEO and CMO
    Managed WordPress hosting provider Kinsta has appointed Jon Penland as its new Chief Executive Officer (CEO) and Matt Reid, formerly of BigCommerce, as its new Chief Marketing Officer (CMO). Penland started at Kinsta nine years prior as a support engineer and rose through roles to COO before taking the CEO position. The former CEO, Mark Gavalda, will remain with the company as founder, chairman, and board member. (Source)
  • Backlinko’s “Seen & Trusted Brand Framework”
    Backlinko introduced the Seen & Trusted Framework for AI Search visibility (ChatGPT, Google AI Mode). Brands must be both Mentioned in the AI answer and Cited as a source. The “Get Seen” playbook focuses on reviews and community discussions (Reddit/Quora), while “Be Trusted” emphasizes authority and original content, requiring cross-departmental coordination. (Source)
  • WordPress Hosting Survey 2025
    The WordPress Hosting Team launched the 2025 Hosting Survey to gather data on hosting setups, technology stacks, and security practices. Conducted annually, results will inform WordPress.org hosting recommendations and be published in a full report. The survey is open until October 15, 2025. (Source)
  • Kinsta at DMEXCO 2025
    Kinsta is sponsoring DMEXCO 2025, Europe’s premier digital marketing and tech event in Cologne, held September 17–18. The Kinsta team will be at Booth E 48a in Hall 6 to discuss their Managed WordPress and Web Application Hosting services, and will be running a giveaway for attendees. (Source)
  • WordCamp Asia 2026: Get Involved
    The Call for Speakers for WordCamp Asia 2026 (April 9–11, 2026, in Mumbai) is open until October 31, 2025. Organizers seek proposals for Lightning, Regular, or Joint Talks, and Hands-On Workshops across themes including AI, Development, Design, and Business. (Source)

🏷️ Exclusive Deals Digest

Ready for a permanent upgrade? Dive into our curated collection of current Lifetime Deals. This is your opportunity to equip your WordPress site with a high-end, premium toolkit at a fraction of the cost, securing substantial savings for years to come.

✨ Fresh Features Rollout

  1. Gutenberg 21.8: Block Visibility Controls
    Gutenberg 21.8 introduces a new Block Visibility control feature, allowing users to hide blocks directly in the editor if they are not meant to be displayed on the frontend. This initial UI paves the way for more granular design control in future releases, alongside improvements to the Accordion and Time To Read blocks. (Source)
  2. FlyWP: pCloud Backup Integration
    FlyWP has added pCloud as a new backup provider, offering more flexibility for WordPress site file and database storage. This allows users to back up directly to their pCloud account, diversifying their storage strategy alongside existing providers like Google Drive. The update also includes security and site transfer reliability fixes. (Source)
  3. Rocket.net: Control Panel Redesign
    Rocket.net has launched a completely rebuilt and redesigned Control Panel. New features include Cloud Backups (10-20x faster and S3-compatible), Dark Mode (based on system settings), a Global Search function, and improved WAF Reporting. This update maintains a familiar experience while enabling continuous, scalable feature development for hosting. (Source)
  4. Astra v4.11.13: Performance and Compatibility
    Astra theme version 4.11.13 focuses on performance optimization and enhanced compatibility. Key improvements include a Faster Customizer Experience via lazy-loading Google Fonts, reducing memory usage. It also enhances LifterLMS Compatibility on the course catalog page and corrects various issues, such as media aspect ratios for video embeds. (Source)
  5. Bricks 2.1: Components and Queries
    Bricks Builder 2.1 introduces several key updates for advanced building. Highlights include Bricks Components as Blocks for Gutenberg integration, Wireframes & Design Sets, and Global Queries & Query Manager. The release also adds the ability to Query Data from APIs, enabling powerful external data integration, and introduces a Leaflet Map Element. (Source)
  6. ACF 6.6: ACF Blocks V3 and UI
    ACF 6.6 is a major release featuring ACF Blocks V3, which moves fields to a larger, dedicated sidebar. This keeps the block’s visual preview visible, improving the editor experience for complex fields like Repeaters. New features also include a separate Display Title for Field Groups and Custom Color Palettes for the Color Picker field. (Source)
  7. OttoKit: New AI Assistant
    OttoKit (formerly SureTriggers) has introduced a new AI Assistant to streamline workflow creation. It offers a modern UI refresh and new features like Multilingual Support (including Spanish, French, and Russian). The update also allows App Connection Sharing among team members and adds Email Templates with a drag-and-drop editor for campaigns. (Source)
  8. WP Rocket 3.20: Rocket Insights Add-on
    WP Rocket 3.20 introduces the new Rocket Insights performance tracking add-on, powered by GTmetrix. This feature displays an average performance score and monitors selected URLs right inside the plugin. Users can run on-demand tests, access detailed GTmetrix reports, and (for Premium users) schedule automated monitoring for tracked pages. (Source)

🆕 Fresh Releases

  • Zen Community Pro: Nonprofit Builder Launches Beta
    The Zen Community Pro platform has entered its beta phase, offering an all-in-one WordPress solution for nonprofits. This tool helps organizations build thriving online communities by streamlining engagement and collaboration for supporters. Key features include robust privacy and security, user profiles, and private messaging, assisting charities and health organizations with connection. (Source)
  • Convoworks: The No-Code AI Powerhouse for WordPress
    Convoworks is a no-code platform that transforms WordPress into an AI-first framework using a drag-and-drop visual interface. It allows users to create Custom APIs, automate scheduled jobs, and build intelligent bots for tasks like Auto-Posting to Twitter. It enhances sites with features like AI-Enhanced Chat and Semantic Search. (Source)
  • Ollie Pro Extensions: Supercharge the Block Editor
    Ollie introduced Ollie Pro Extensions, a suite of enhancements that supercharge existing WordPress blocks. They seamlessly integrate into the block editor, adding professional-grade capabilities like Advanced Grid Controls for responsive layouts and an Animation Designer. This release elevates Ollie into a complete, modern site-building experience for power users. (Source)
  • Telex: AI-Assisted Authoring for WordPress Blocks
    Telex by Automattic AI is an experimental, AI-assisted authoring environment for WordPress blocks. This tool helps users generate and create content more efficiently within the block editor, leveraging AI to streamline the writing and design process. The system is an exploration into the future of site creation and is currently for desktop use. (Source)

🗓️ Mark Your Calendar 

If you’re looking for opportunities to network and learn, check out these upcoming WordPress events and meetups:

That’s a wrap for this week’s WPDigest! Stay tuned for more exciting WordPress updates next week.

Want to feature your WordPress product, service, or update news? Submit it for free using our form, helping spread the goodness of WordPress!

đź“© Enjoyed this digest? Share it with your network!

Leave a Comment

Your email address will not be published. Required fields are marked *