Back to Archive

Patch now, and the AI hangover

Two things defined this week. WordPress shipped an emergency security release: 7.0.2 patches an unauthenticated SQL injection that can be chained into remote code execution, and the severity was high enough that WordPress.org switched on forced updates. If you look after sites, that is today's job before anything else.

The second is slower moving but matters more over time. Agencies are reporting client AI fatigue, and the research suggests most people do not want more AI stuffed into their tools. Worth sitting with if your roadmap assumes otherwise.


Beginner

WordPress 7.0.2 patches a critical hole, update today

The 7.0.2 security release fixes one critical and one high-severity issue: an unauthenticated SQL injection that can be chained into remote code execution and full site takeover. WordPress.org enabled forced updates because of the severity, but check every site you manage rather than assuming the update landed.

A practical guide to killing WordPress spam

WPBeginner's step-by-step walkthrough covers comments, contact forms, and user registration, the three doors most sites leave propped open. Less glamorous than the AI news, and far more likely to save you an hour every week.

Host bot protection or Cloudflare: which one do you need?

Bot traffic now outweighs human visits on a lot of sites, and this compares host-level bot filtering against Cloudflare's. A good way to work out whether you are paying twice for overlapping defences.

Developer

The post editor goes full iframe in 7.1

The post editor has always rendered blocks straight into the admin page while the Site Editor used an iframe. That split ends in 7.1, so any block relying on admin-page styles, globals, or DOM assumptions needs a look before the August release.

AI is widening WordPress's attack surface

Every assistant, content generator, and developer agent bolted onto an enterprise WordPress estate is another way in. Human Made maps how the security picture shifts once agents hold write access to your CMS.

Why delaying updates is the bigger risk

Attackers begin scanning for unpatched installs within hours of a disclosure, which turns a deferred update into an open invitation. Pointed timing in a week when core shipped an emergency patch.

Business

AI fatigue is an opening for agencies

Clients are finding that AI tools on their own do not solve their problems, and that disillusionment is creating demand for people who can. The WP Minute's Agency Action argues this is an opportunity rather than a threat.

Do you owe tax on your AI app?

Selling an AI app, agent, or chatbot usually triggers sales tax, VAT, or GST somewhere, and the rules follow your buyer rather than you. Freemius lays out what applies before a tax authority explains it to you.

What to nail before you quote a multilingual build

A client asking for the site "in Spanish too" is describing a project roughly three times the size they think it is, touching the theme, URLs, database, and SEO. Read this before you put a number on it.

Non-WordPress

No, people don't want more AI in their life

The assumption that users are hungry for AI features does not survive contact with the evidence. A useful corrective if your product roadmap is banking on demand that may not be there.

The cost of saying yes has changed

Writing code got cheap, but owning it did not. GitHub offers a framework for judging which changes are genuinely low-cost now that generating them is close to free.

Microsoft patches a record 570 flaws

July's Patch Tuesday cleared nearly triple last month's haul, which was itself a record. The patching treadmill is speeding up across the whole stack, not just in WordPress.