Back to Archive

7.1 lands at WordCamp US

WordCamp US is on in Phoenix this week, and it comes with a headline: WordPress 7.1 ships Wednesday, August 19. It is a big release, with client-side media processing, new design tools, and a broader Abilities API, so we lead with what it means for you below.

It was also a rough week for security. Two widely installed plugins shipped fixes for serious flaws, core pushed another patch, and there is a fair argument that AI is shrinking the gap between disclosure and attack. Patch first, read second.


Beginner

WordPress 7.1 lands Wednesday at WordCamp US

The 7.1 release ships August 19, timed to WordCamp US in Phoenix, and it brings client-side media processing, new design tools, and an expanded Abilities API. Kinsta's overview is the fastest way to see what changes for you before the update prompt appears.

WordPress now has an official browser extension

The new open-source extension for Chrome and Safari lets logged-in users hide the admin bar, hop between site and dashboard, and manage installs from the toolbar. Built by 10up founder Jake Goldman, it is a small quality-of-life win for anyone who juggles several sites.

Hit a 90+ PageSpeed score for free

WPShout walks the free performance stack, caching, image optimization, and theme discipline, with measured before-and-after numbers instead of vague promises. A good weekend project that pays back on every page load.

Developer

600,000 sites exposed by a Forminator flaw

An unauthenticated arbitrary file upload in Forminator Forms puts more than 600,000 sites at risk of full compromise. If you run Forminator anywhere, update it before you read the rest of this issue.

The 7.0.4 patch closes an Imagick RCE

WordPress 7.0.4 changes how uploads reach ImageMagick, closing a path that let an author-level user reach remote code execution through a disguised PNG. Patchstack's breakdown is worth reading rather than clicking past the update.

What 7.1 changes for developers

The developer field guide for 7.1 is out, covering responsive block styles, pseudo-state support, a new SVG Icon API, and the always-iframed post editor. Read it before the release lands so nothing in your themes or plugins gets caught out.

AI is speeding up WordPress exploit research

Sucuri walks through how AI tooling is compressing the time between a vulnerability existing and being weaponized at scale. Sobering context for why this week's plugin patches matter more than they used to.

Business

Is AI going to kill WordPress?

The LinkedIn doom posts say WordPress is finished; the reality is more complicated and more interesting. A level-headed take on where AI site builders threaten WordPress and where they do not.

Real-time WordPress is coming

WPSignal's creator makes the case for Google Docs-style collaborative editing built into WordPress, and what real-time infrastructure would unlock. A glimpse at a capability the platform has never really had.

What the AI era asks of hosting

ScalaHosting's CTO on how hosting companies are rethinking their role as AI reshapes how sites get built and run. Useful if you are choosing a host or reselling one to clients.

Non-WordPress

The EU's new AI labelling rules

Fresh EU guidance spells out when AI features must be labelled and why a sparkle icon does not cut it. Worth knowing if you ship anything AI-powered to European users.

Find out who is tracking you

Krebs highlights a new service that untangles the ad-tech firms and data brokers behind the sites and apps you use every day. A rare look behind a curtain that is usually kept deliberately murky.

DDoS attacks jumped 519% this year

Cloudflare's H1 report records a 519% surge in hyper-volumetric DDoS attacks, driven by DNS reflection and geopolitical conflict. A reminder that the baseline threat level under every site keeps climbing.