Latest Product Updates and Feature Enhancements on WordPress.org

 

WordPress 7.1 – WordPress.org

WordPress 7.1 introduces responsive design features, allowing users to customize block styles for different screen sizes without CSS. The update includes a new media editor for image cropping and met...adata editing, improved media handling with browser-based compression, and enhanced accessibility features. These updates aim to streamline content management and web development processes.

Read on →
 

WordPress 7.1 “Mary Louâ€�

WordPress 7.1 "Mary Lou" introduces new features for enhanced content management and responsive design. Key updates include a persistent admin bar, advanced media editing tools, and new blocks for pl...aylists and tabs. The release also improves image processing and accessibility, offering a more consistent and flexible editing experience. Developers benefit from expanded APIs and a new design system.

Read on →
 

Introducing the WordPress Browser Extension – WordPress News

WordPress has launched an official browser extension for Google Chrome, Chromium-based browsers, and Safari, enhancing user experience by hiding the admin bar while keeping essential shortcuts access...ible. The open-source extension aids developers and content creators by providing tools like block boundary visualization and cache busting, all without requiring additional software installation.

Read on →
 

WordPress 7.1 Release Candidate 3

WordPress has released the third release candidate (RC3) for WordPress 7.1, which includes over 90 updates and fixes. The final release is scheduled for August 19, 2026. Users are encouraged to test ...the RC3 version to ensure stability and performance. The release highlights the importance of community involvement in testing and contributing to the open-source platform.

Read on →
 

WordPress 7.0.3 release – WordPress News

WordPress 7.0.3 is now available, featuring several security fixes to address vulnerabilities such as cross-site scripting (XSS) and privilege escalation issues. Users are advised to update immediate...ly. The release includes backports for older versions and details on specific vulnerabilities, emphasizing WordPress's commitment to security.

Read on →
 

WordPress 7.1 Release Candidate 1

WordPress has released the first Release Candidate (RC1) for WordPress 7.1, featuring over 145 updates and fixes, including new APIs for icons, speculative loading configuration, and shareable revisi...ons. The final release is scheduled for August 19, 2026. Users are encouraged to test the RC1 version to ensure stability and performance.

Read on →
 

WordPress Plugin Backdoor Risk

A critical security vulnerability, CVE-2026-18072, was discovered in the Advanced Responsive Video Embedder plugin for WordPress, affecting around 20,000 installations. Wordfence PRISM identified the... issue, leading to the plugin's download repository closure. Administrators are advised to audit accounts, reset credentials, and block connections to prevent further breaches.

Read on →
 

WordPress 7.1 Beta 4 – WordPress News

WordPress 7.1 Beta 4 is now available for testing, featuring over 114 updates and fixes since Beta 3. This release focuses on bug fixes in the Editor and Core, with enhancements for smoother editing ...and clearer tag displays. The final release of WordPress 7.1 is scheduled for August 19, 2026.

Read on →
 

Development – WordPress News

WordPress has released a new browser extension for Google Chrome, Chromium-based browsers, and Safari, enhancing user experience by allowing logged-in users to hide the admin bar while keeping shortc...uts accessible. Additionally, WordPress 7.1's first Release Candidate is available for testing, emphasizing its ongoing development and readiness for evaluation in non-production environments.

Read on →
 

Hackers Actively Exploiting Recently Patched WordPress Vulnerabilities

Hackers are exploiting two critical vulnerabilities in WordPress, affecting millions of websites. These vulnerabilities have been patched in updated WordPress versions, but sites that haven't applied... the updates are at risk. The vulnerabilities highlight the need for UK organizations to ensure all WordPress sites are updated promptly to prevent unauthorized access and potential data breaches.

Read on →
 

CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE

CISA has added two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to its Known Exploited Vulnerabilities catalog. These flaws enable unauthenticated remote code execution on defau...lt WordPress installations. WordPress has released security updates to address these vulnerabilities, urging administrators to verify successful upgrades and implement temporary mitigations if immediate patching is not possible.

Read on →
 

WordPress 7.1 Beta 3 – WordPress News

WordPress 7.1 Beta 3 is now available for testing, featuring improvements in styling and media uploads. The update allows selective global application of style changes and resolves issues with animat...ed GIFs and HEIC image uploads. Developers can explore updates to WordPress Coding Standards version 3.4.0. The final release is scheduled for August 19, 2026.

Read on →
 

WordPress Bugs Exploited After Patch, Millions At Risk

WordPress recently patched critical vulnerabilities in its platform, but hackers have already begun exploiting these flaws, putting millions of websites at risk. Despite WordPress's efforts to push e...mergency updates, many sites remain vulnerable, highlighting the importance of immediate patching. The vulnerabilities affect versions 6.9.0 through 7.0.1, with an estimated tens of millions of sites potentially exposed.

Read on →
 

Hackers are exploiting recently patched WordPress bugs, putting ...

WordPress patched two critical security vulnerabilities in its software, affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. Despite the patches, hackers are exploiting these bugs, risking millions... of websites. WordPress enabled forced updates, and companies like Cloudflare are blocking attacks. Automattic protected its hosted sites before the update release.

Read on →
 

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WordPress has released patches for two critical vulnerabilities, WP2Shell, affecting versions 6.9.0 to 7.0.1. These vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, allow unauthenticate...d remote code execution. WordPress has enabled forced updates via its auto-update system to mitigate risks.

Read on →
 

CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained

The wp2shell exploit chain in WordPress core, identified as CVE-2026-63030 and CVE-2026-60137, allows unauthenticated remote code execution by exploiting a request-handling bug in the batch REST endp...oint. This vulnerability affects default WordPress installations and requires no plugins or special configurations. The Picus Platform enables teams to simulate wp2shell attacks to test and validate security controls.

Read on →
 

Active Exploitation Alert: WP2Shell Critical WordPress Core ...

WordPress has identified critical vulnerabilities, WP2Shell, in its core system, affecting versions 6.9 and 7.0. These flaws allow unauthenticated remote code execution, posing a significant threat t...o millions of sites. WordPress urges immediate updates to versions 6.9.5 or 7.0.2 to mitigate risks. Security firms report widespread exploitation, emphasizing the need for urgent patching and enhanced security measures.

Read on →
 

wp2shell: Critical WordPress vulnerability allows code injection via API

WordPress has released updates to address two critical vulnerabilities, CVE-2026-60137 and CVE-2026-63030, which allow code injection via the REST API. Administrators are urged to update to versions ...7.0.2, 6.9.5, 6.8.6, or 7.1 beta 2 to prevent potential large-scale attacks.

Read on →
 

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell ...

WordPress has released a security update addressing critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in its core software. These flaws allow remote code execution on versions 6.9.x and 7....0.x. WordPress has enabled forced automatic updates to mitigate the risk, urging site owners to update to versions 7.0.2 or 6.9.5 immediately.

Read on →
 

WordPress releases emergency update for critical 'wp2shell' RCE flaw

WordPress has released emergency security updates to address the critical 'wp2shell' vulnerability chain, which can allow remote code execution on websites using WordPress 6.9 through 7.0.1. The upda...te fixes two vulnerabilities, including an unauthenticated SQL injection flaw and a REST API vulnerability. Administrators are urged to apply the patches immediately to prevent exploitation.

Read on →
 

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

WordPress has released patches for critical "wp2shell" remote code execution vulnerabilities affecting versions 6.9.x and 7.0.x. These flaws, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated ...remote code execution. Administrators are urged to update to versions 7.0.2 or 6.9.5 immediately to prevent exploitation. Cloudflare has deployed WAF protections, but patching remains essential.

Read on →
 

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites ...

WordPress.org has released an emergency patch for a critical RCE vulnerability, "wp2shell," affecting millions of sites. The flaw, impacting versions 6.9.0 to 7.1 beta, allows unauthenticated attacke...rs to execute code remotely. WordPress.org has force-pushed updates to mitigate risks, urging immediate patching due to the exploit's severity and widespread impact.

Read on →
 

WordPress 7.0.2 Release – WordPress News

WordPress has released version 7.0.2, addressing critical and high-severity security vulnerabilities. This update includes fixes for SQL injection and REST API issues, with forced updates enabled for... affected sites. Users are advised to update immediately to enhance security.

Read on →
 

wp2shell: Pre Authentication RCE in WordPress Core

A pre-authentication RCE vulnerability has been discovered in WordPress Core, affecting versions 6.9.0 to 7.0.1. Users are advised to update to version 7.0.2 or 6.9.5 to mitigate risks. Temporary mea...sures include blocking anonymous access to certain APIs.

Read on →
 

WordPress 7.1 Beta 1 – WordPress News

WordPress has released the beta version of WordPress 7.1, introducing new features such as enhanced styling controls, improved media handling, and a more personalized admin experience. The update inc...ludes responsive design capabilities, inline notes, and a smoother media experience with client-side processing. Developers benefit from expanded APIs and improved authentication methods. The final release is scheduled for August 19, 2026.

Read on →
 

ShapedPlugin Pro WordPress Plugins Supply Chain Attack: Credential ...

A supply chain attack compromised several ShapedPlugin Pro WordPress plugins, affecting only paying customers. Malicious code was injected into plugin updates, leading to credential theft and data ex...filtration. The attack did not affect plugins hosted on WordPress.org. Organizations using these plugins are advised to update to patched versions and take immediate security measures.

Read on →
 

WordPress 7.0 WordPress.org

WordPress 7.0 introduces significant updates, including enhanced navigation design, AI integration, and improved accessibility. Users can now create customized navigation overlays, manage AI service ...connections, and utilize a new font library across all themes. The update also enhances performance with better image loading and block stylesheet management. Accessibility improvements include better media management and a refreshed admin interface.

Read on →
 

WordPress 7.0 Armstrong WordPress News

WordPress has launched version 7.0, named "Armstrong," featuring a modernized dashboard and AI integration. This release introduces enhanced customization and development tools, including an AI Clien...t in Core, new blocks, and design tools. The update aims to improve user experience with a sleek admin theme and expanded developer capabilities, marking a significant step in WordPress's evolution.

Read on →
 

McCrossen Marketing Releases McCrossenSEO Free on WordPress.org

McCrossen Marketing has released the McCrossenSEOTM plugin for free on the WordPress.org directory. This plugin offers a comprehensive SEO toolkit for WordPress users, bundling features typically spl...it across paid upgrades in competing plugins. It includes on-page and technical SEO capabilities, WooCommerce product SEO, and tracking pixel injection, all without requiring a paid license or add-ons.

Read on →
 

WordPress 7.0 Will Ship Without Real-Time Collaboration

WordPress has decided to exclude the real-time collaboration feature from its upcoming 7.0 release. The decision, announced by Matt Mullenweg, stems from concerns over the feature's robustness, inclu...ding issues with server load and recurring bugs. This feature was part of Phase 3 in WordPress's development roadmap. The community largely supports the decision, viewing it as a move towards a more stable release.

Read on →
 

WordPress 7.0 Release Candidate 3 WordPress News

WordPress 7.0 Release Candidate 3 (RC3) is now available for testing. This version is a key milestone in the development cycle, with the final release scheduled for May 20, 2026. Users are encouraged... to test RC3 on non-production sites using various methods, including direct download and WP-CLI. Over 143 issues have been addressed since RC2. Real Time Collaboration will not be included in this release.

Read on →
 

Popular WordPress Redirect Plugin Hid Backdoor

A popular WordPress redirect plugin was found to contain a hidden backdoor, affecting over 70,000 installations. The backdoor, present in versions from 2020 to 2021, allowed attackers to inject malic...ious code via an external server, posing significant security risks. Users are advised to remove the plugin and replace it with a clean version from official sources to mitigate potential threats.

Read on →
 

Innovative WordPress Plugin Cuts AI Data Usage and Energy Costs

The Chancery Lane Project has introduced a new open-source WordPress plugin that reduces AI data usage and energy costs. The plugin, "WordPress Markdown for Agents," simplifies webpage content for AI... systems by removing unnecessary elements, cutting data transfer by up to 80%. This innovation could lead to significant energy savings across millions of WordPress sites globally.

Read on →
 

WordPress Plugin Backdoor Compromises Thousands of Sites in 2026

In April 2026, a supply chain attack compromised over 30 WordPress plugins, including the 'Essential Plugin' portfolio, affecting thousands of sites. The attacker, 'Kris,' injected a backdoor allowin...g unauthorized code execution. This incident highlights vulnerabilities in plugin ecosystems and the need for rigorous security measures in third-party software integrations.

Read on →
 

Hack of 30 WordPress Plugins Leads to Malware Spread on Thousands of ...

WordPress.org developers swiftly addressed a security breach involving over 30 compromised plugins from the EssentialPlugin bundle. The breach, which began in 2025, involved a backdoor that allowed u...nauthorized access to WordPress sites. A forced update has been deployed to block the malware, although manual checks are needed to ensure complete removal.

Read on →
 

WordPress.org blog: WordPress 6.9 Gene

WordPress.org has released WordPress 6.9, named "Gene," honoring jazz pianist Gene Harris. This version introduces significant upgrades, including a new Notes feature for block-level commenting, enha...ncing team collaboration and content creation.

Read on →
 

Trusted WordPress plugins carried a hidden backdoor for months before ...

A supply chain attack compromised the WordPress plugin ecosystem after a buyer acquired a portfolio of plugins and inserted malicious code into an update. The code, dormant for eight months, activate...d on April 6, 2026, modifying wp-config.php files. WordPress.org responded by shutting down affected plugins and issuing a forced update, but the update did not fully clean infected sites.

Read on →
 

WordPress Plugin Vulnerability Exploited to Spread Malware

WordPress.org swiftly responded to a security breach affecting over 30 plugins in the EssentialPlugin suite, which were compromised with malicious code. This code created unauthorized access to websi...tes, leading to spam and redirections. The WordPress team deactivated the affected plugins and enforced updates to stop the malware's communication, although the core configuration file remains vulnerable.

Read on →
 

Trusted WordPress Plugins Weaponized in Delayed Malware Campaign

A malware campaign exploited trusted WordPress plugins, including Countdown Timer Ultimate, to deliver SEO spam and backdoor access. The attack, initiated months after a plugin acquisition, highlight...s vulnerabilities in the WordPress plugin ecosystem, particularly in ownership transfer oversight and code review processes.

Read on →
 

Dozens of WordPress plugins hijacked to target thousands of sites

A hacker exploited 31 WordPress plugins, injecting backdoors to gain unauthorized access to thousands of websites. The plugins, developed by Essential Plugin, were sold in 2025 and later compromised.... The injected code was sophisticated, using Ethereum smart contracts to evade detection. WordPress has since removed the malicious plugins from its repository.

Read on →
 

Malicious Backdoor Discovered in Popular WordPress Plug-ins

A backdoor was discovered in several WordPress plug-ins following the acquisition of Essential Plugin, leading to the distribution of malicious code. This security breach, affecting thousands of inst...allations, underscores the risks of supply chain attacks in software. The compromised plug-ins have been removed from the WordPress directory, and site administrators are advised to uninstall affected extensions.

Read on →
 

WordPress Plugin Backdoor Hits 20K+ Sites in Supply Chain Attack

Over 20,000 WordPress sites were compromised in a supply chain attack after a plugin developer's portfolio was acquired and backdoored. The malicious code, hidden for months, exploits Ethereum smart ...contracts to evade detection. Despite WordPress's security updates, the backdoor persists, highlighting a systemic vulnerability in plugin ownership changes and supply chain security.

Read on →
 

WordPress plugin suite hacked to push malware to ...

A suite of over 30 WordPress plugins from EssentialPlugin was compromised, allowing unauthorized access and malware injection into websites. The backdoor, active since August 2025, was discovered by ...Austin Ginder of Anchor Hosting. WordPress.org responded by closing affected plugins and issuing a forced update to neutralize the threat, although some vulnerabilities remain unpatched.

Read on →
 

Backdoors discovered in 31 WordPress plugins, added in updates after ownership transfer.

Backdoors have been discovered in 31 WordPress plugins following ownership transfers, posing security risks. These vulnerabilities could allow unauthorized access to websites using these plugins, hig...hlighting significant security concerns for WordPress users.

Read on →
 

Smart Slider updates hijacked to push malicious WordPress, Joomla versions

Hackers compromised the update system for Smart Slider 3 Pro, affecting WordPress and Joomla sites by embedding a backdoor in version 3.5.1.35. The malware creates hidden admin accounts and steals da...ta. Users should update to version 3.5.1.36 or earlier versions, remove malicious elements, and secure their sites with recommended actions like reinstalling core files and enabling two-factor authentication.

Read on →
 

WordPresss Troubled Real-Time Collaboration Feature

WordPress has delayed the release of version 7.0 due to instability in the real-time collaboration (RTC) feature. The RTC allows multiple users to edit content simultaneously, but issues with data st...orage have caused setbacks. The feature has been tested in beta with enterprise customers, revealing performance limitations. The delay has sparked debate on whether RTC should be a core feature or a plugin, with some questioning the necessity of including it in the core.

Read on →
 

Cloudflare unveils new plugin-secure CMS to compete with WordPress ...

Cloudflare has introduced EmDash, a new open-source CMS designed to compete with WordPress by addressing plugin security issues. EmDash isolates plugins using Cloudflare's Dynamic Workers, enhancing ...security compared to WordPress's direct plugin access. It also features AI capabilities and supports internet-native payments. Despite its innovations, skepticism exists about its ability to replace WordPress due to compatibility and network effects.

Read on →
 

Cloudflare announces secure, open-source, WordPress-compatible CMS

Cloudflare has introduced EmDash, a secure, open-source CMS designed to be compatible with WordPress plugins and themes. EmDash aims to address WordPress's security vulnerabilities by isolating plugi...ns in separate environments. The CMS supports distributed infrastructure, offering flexibility in hosting and scaling, and includes features for new web monetization models. Currently in developer beta, EmDash represents Cloudflare's expansion into application development and hosting.

Read on →
 

WordPress Delays Release Of Version 7.0 To Focus On Stability

WordPress has delayed the release of Version 7.0 to focus on stabilizing the Real-Time Collaboration feature. This decision, announced by co-founder Matt Mullenweg, emphasizes the need for extreme st...ability and extended testing. The delay allows more time to address performance concerns and database design issues, ensuring compatibility and reliability before the final release.

Read on →
 

WordPress 7.0 Release Candidate 2

WordPress has released the second Release Candidate (RC2) for WordPress 7.0, available for testing. This milestone is crucial for ensuring the software's stability before its final release on April 9..., 2026. Users are encouraged to test RC2 on non-production sites and report issues. Key features include real-time collaboration and pattern editing. Plugin and theme authors should update compatibility to version 7.0.

Read on →
 

WordPress 7.0 Release Candidate 1

WordPress has released the first Release Candidate (RC1) for version 7.0, introducing over 134 updates and fixes since Beta 5. Key features include an AI Connectors Screen and a Command Palette short...cut. The final release is scheduled for April 9, 2026. Users are encouraged to test RC1 and provide feedback to ensure a stable final version.

Read on →
 

WordPress 6.3 WordPress.org

WordPress 6.3 introduces significant enhancements to the Site Editor, allowing seamless template and content management. Key features include the Command Palette for quick navigation, improved perfor...mance with 24% faster LCP times, and over 500 new features and enhancements. The update also includes 170+ performance updates, support for the Scripts API, and improved image loading times.

Read on →
 

WordPress 6.4 WordPress.org

WordPress has released version 6.4, introducing the Twenty Twenty-Four theme designed for diverse creative and business needs. This update includes over 100 performance enhancements, new site editing... capabilities, and accessibility improvements. Key features include a refreshed Command Palette, Block Hooks for developers, and lightbox functionality for images. The release emphasizes flexibility, customization, and improved user experience.

Read on →
 

WordPress 6.5 WordPress.org

WordPress 6.5 introduces new features and enhancements, including a Font Library for typography management, improved background and shadow tools, a more intuitive link-building experience, and new Da...ta Views for organizing site information. The release also boasts significant performance and accessibility improvements, with over 110 performance updates and 65 accessibility enhancements. Developers benefit from the Interactivity API for building interactive experiences and the Block Bindings API for connecting blocks to dynamic content.

Read on →
 

WordPress 6.6 WordPress.org

WordPress 6.6 introduces new design and functionality features, including enhanced color palettes, font sets, and a new rollback option for plugin auto-updates. The update also offers performance imp...rovements, accessibility enhancements, and modern pattern management. Users can now customize shadows, manage grid blocks, and use new shortcuts, improving the overall site editing experience.

Read on →
 

WordPress 6.7 WordPress.org

WordPress 6.7 introduces the modern Twenty Twenty-Five theme, offering enhanced design options and a new 'Zoom out' mode for simplified editing. The update includes performance improvements, accessib...ility enhancements, and support for HEIC images. Users can now connect blocks to custom fields with ease, and enjoy expanded design tools and improved interactivity.

Read on →
 

WordPress 6.8 WordPress.org

WordPress 6.8 introduces significant enhancements, including a refined Style Book for easier theme customization, improved editor features, faster page loads through speculative loading, and stronger... password security with bcrypt hashing. The update also includes over 100 accessibility improvements and performance optimizations, enhancing the overall user experience and site management capabilities.

Read on →
 

WordPress 6.9 WordPress.org

WordPress 6.9 introduces new features like collaborative Notes, a Command Palette, and visual drag-and-drop design. It enhances performance with improved loading metrics and accessibility with over 7...0 fixes. New blocks include accordion, time-to-read, and math blocks. The update also introduces the Abilities API for developers and offers typography options for text blocks.

Read on →
 

All Posts WordPress News

WordPress has released version 6.9.4, addressing unresolved security issues from previous updates. This update is crucial for maintaining site security. Additionally, WordPress 7.0 is in development,... with its second release candidate available for testing. Users are advised to test these versions on non-production sites.

Read on →
 

WordPress.com now lets AI agents write and publish posts, and more

WordPress.com introduces AI agents to automate drafting, editing, and publishing content on websites. These agents can manage comments, update metadata, and organize content using natural language co...mmands. This innovation aims to streamline website creation and management, allowing AI to handle tasks traditionally done by humans, while maintaining user oversight.

Read on →
 

WordPress.com lets AI agents write, publish, and manage your site

WordPress.com has introduced write capabilities to its Model Context Protocol (MCP) integration, allowing AI agents like Claude and ChatGPT to create and manage content on websites. This update enabl...es AI to draft posts, build pages, and manage site elements with human approval. The feature is available on all WordPress.com paid plans, enhancing the platform's AI integration capabilities.

Read on →
 

Vibe Coding Plugins? Validate With Official WordPress Plugin Checker

WordPress.org has released version 1.9.0 of its Plugin Check Plugin, designed to help developers ensure their plugins meet WordPress.org's standards for compatibility, security, and best practices. T...he update includes AI connectivity, enhanced block compatibility for WordPress 7.0, and checks for external URLs in admin menus. It aims to streamline plugin acceptance into the WordPress repository.

Read on →
 

WordPress Just Landed in Your Browser

WordPress launched my.WordPress.net, a browser-based, persistent workspace requiring no sign-up or hosting. Built on WebAssembly, it offers private, serverless WordPress environments for drafting and... personal use. This innovation aims to expand WordPress installations from millions to billions by simplifying access and usage. Users can export sites to public hosts, and future updates will include peer-to-peer sync and cloud publishing.

Read on →
 

WordPress Runs in Your Browser Now

WordPress.org launched my.WordPress.net, a browser-based WordPress environment that requires no sign-up or hosting. It offers a private, device-specific workspace with tools like a personal CRM, RSS ...reader, and AI workspace. Built on WordPress Playground, it allows users to develop plugins and manage content without technical barriers, emphasizing digital sovereignty.

Read on →
 

WordPress has released 'My WordPress, ' which allows users to build a fully functional WordPress installation using only a web browser, enabling plugin support, backups and restores anywhere, and even functioning as an RSS reader.

WordPress has launched 'My WordPress,' enabling users to create a complete WordPress setup via a web browser. This tool supports plugins, backups, restores, and functions as an RSS reader, enhancing ...user flexibility and functionality.

Read on →
 

WordPress Launches Browser-Based Site Builder for Private Use

WordPress.org has launched my.WordPress.net, a browser-based tool for creating private sites without the need for signup or hosting. This tool is designed for drafting, journaling, and experimentatio...n, not public use, marking a shift from WordPress's traditional hosting model. It aims to lower barriers for new users amid competition from no-code builders, potentially converting them into paying customers later.

Read on →
 

WordPress launches an in-browser website creator

WordPress.org has introduced a new in-browser website creator accessible via my.WordPress.net. This tool allows users to build private websites without needing a WordPress account, hosting plan, or d...omain. It is designed for creating drafts, journaling, and experimenting with plugins and themes. The workspace, based on WordPress Playground, offers storage starting at 100MB and includes various plugins like a personal RSS reader and an AI assistant.

Read on →
 

WordPress Launches In-Browser Website Creator: No Sign-Up, No Hosting ...

WordPress.org has launched my.WordPress.net, an in-browser website creator that allows users to build private websites without sign-up or hosting. This tool, based on WordPress Playground technology,... supports plugins and themes while keeping all data local to the browser. It's ideal for private use and experimentation, offering a seamless way for both new and experienced users to explore WordPress features.

Read on →
 

WordPress Security Release 6.9.4 Fixes Issues 6.9.2 Failed To Address

WordPress released version 6.9.4 to address vulnerabilities not fully fixed in previous updates 6.9.2 and 6.9.3. The update resolves ten security issues, including a medium-severity XML External Enti...ty Injection flaw. WordPress advises immediate updates to ensure site security.

Read on →
 

WordPress debuts a private workspace that runs in your browser via a ...

WordPress has introduced my.WordPress.net, a private workspace that operates entirely in the browser, allowing users to set up and manage sites without hosting or domain registration. This service, p...owered by WordPress Playground, supports personal publishing and includes tools like a Personal CRM and AI Workspace. Sites are private and stored in the browser, with options to move to a public host.

Read on →
 

Your Browser Becomes Your WordPress

WordPress introduces my.WordPress.net, a browser-based platform that eliminates the need for sign-ups, hosting plans, or domain decisions. Built on WordPress Playground, it offers a private, persiste...nt environment for personal use, featuring an app catalog with pre-configured experiences. This innovation democratizes digital sovereignty, allowing users to explore, learn, and build without barriers.

Read on →
 

WordPress 6.9.3 and 7.0 beta 4

WordPress released version 6.9.3 to address security issues and a bug affecting some themes. The upcoming WordPress 7.0 beta 4, scheduled for March 12, 2026, includes additional security patches and ...updates. Users are advised to test this beta version on non-production sites.

Read on →
 

WordPress 7.0 Beta 3 WordPress News

WordPress has released Beta 3 of its upcoming 7.0 version, available for testing. This beta includes over 148 updates and fixes, with significant improvements in the Editor and Core. Notably, it enha...nces AI integration through dynamic registration of providers. The final release is scheduled for April 9, 2026.

Read on →
 

WordPress 6.9.1 Maintenance Release WordPress News

WordPress 6.9.1, a minor maintenance release, is now available, addressing 49 bugs in Core and the Block Editor. This update improves areas like the block editor, mail, and classic themes. Users with... automatic updates will receive it automatically. The next major release, WordPress 7.0, is scheduled for April 9, 2026.

Read on →
 

New AI Agent Skill for WordPress

WordPress has introduced a new AI agent skill, wp-playground, designed to streamline the testing of WordPress plugins and themes. This tool allows AI agents to quickly start WordPress, mount code, an...d verify functionality, enhancing the development process. It reduces setup time significantly and supports integration with tools like curl and Playwright. The project is open for community contributions on GitHub.

Read on →
 

WordPress Playground Brings Speed, Stability, and Momentum

WordPress Playground introduced significant updates in 2025, enhancing speed, compatibility, and tooling for developers and educators. Key improvements include a 42% reduction in response time, broad...er plugin support, and enhanced database tools like phpMyAdmin. The platform now supports 99% of the top 1,000 plugins, fostering reliable plugin previews and experimentation. These updates position Playground as a versatile environment for testing and sharing WordPress experiences globally.

Read on →
 

WordPress 6.8.3 Release

WordPress 6.8.3 is a security release addressing a data exposure issue and a cross-site scripting vulnerability. Users are advised to update immediately. The next major release, version 6.9, is plann...ed for December 2, 2025.

Read on →
Show More

Corporate News and Organizational Updates on WordPress.org

 

Attacker Bought 30 WordPress Plugins on Flippa and Backdoored ...

An attacker bought 30 WordPress plugins on Flippa, inserted a PHP deserialization backdoor, and activated it after eight months, affecting 400,000 installations. WordPress.org quickly closed the plug...ins and issued an update, but compromised sites needed manual fixes. This incident highlights vulnerabilities in plugin ecosystems and the need for enhanced security measures.

Read on →
 

Someone Bought 30 WordPress Plugins Just to Backdoor Them

WordPress.org permanently closed 31 plugins after discovering a backdoor planted by a buyer who acquired the plugins on Flippa. The backdoor allowed remote code execution, leading to a sophisticated ...supply chain attack. The plugins, originally developed by WP Online Support, were sold to a buyer who exploited them for black-hat SEO. WordPress.org's response included a forced update to neutralize the threat.

Read on →
 

WordPress Security Incident Reveals Hidden Backdoor Inserted Months ...

A security breach in the WordPress ecosystem was uncovered, involving malicious code in plugins from Essential Plugin, a company acquired by a buyer known as "Kris." The code created a backdoor, allo...wing remote access to websites. The attack, which began in August 2025, was activated in April 2026, affecting numerous sites. WordPress.org removed the compromised plugins, but many sites remain vulnerable due to infected configuration files.

Read on →
 

Someone bought 30 WordPress plugins and planted backdoors in all of them

WordPress.org faced a significant security breach when an attacker purchased over 30 plugins, planted backdoors, and exploited them to serve SEO spam. The attack highlighted a structural vulnerabilit...y in WordPress's plugin governance, as there's no mechanism to review ownership transfers or require code signing for updates. WordPress.org responded by closing the affected plugins, but the incident underscores the need for stricter security measures.

Read on →
 

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

A security breach involving 30 WordPress plugins was discovered, where a backdoor was planted by a new owner after acquiring the plugins. WordPress.org closed the compromised plugins and issued a for...ced update to neutralize the threat. However, the malware persisted, highlighting a significant security oversight in plugin ownership transfers on WordPress.org.

Read on →