Blog

THE LATEST WORDPRESS NEWS

Contact Form 7 6.2 Requires PHP 8.3 and WordPress 7.1: What It Means for Your Site

Contact Form 7 6.2 raised its minimums from PHP 7.4 to 8.3 and WordPress 6.7 to 7.1. What happens to sites below the bar, and where it can still...

Read More
October 8, 2026, Written by 0 comment

WordPress 7.1.3: Seven Security Fixes in Core

WordPress 7.1.3, released 6 October 2026, fixes seven security issues in core, including two cross-site scripting flaws and a SQL injection in export.

Read More
October 8, 2026, Written by 0 comment

WordPress 7.1.2: Fifth Core Security Release Since July

WordPress 7.1.2, released 22 September 2026, fixes a critical unauthenticated file inclusion flaw. It is the fifth core security release since 17 July.

Read More
September 22, 2026, Written by 0 comment

WordPress Vulnerability Disclosures Hit 11,334 in 2025

Patchstack recorded 11,334 new WordPress vulnerabilities in 2025, up 42%. Our own analysis of the CVE record shows 2026 running level, not higher.

Read More
September 2, 2026, Written by 0 comment

WordPress 7.1 Breaks WP Rocket on Elementor Pro Sites: What Happened and How to Spot It

WordPress 7.1 changed how hook callbacks are identified. On sites running WP Rocket and Elementor Pro under PHP 8, that is a fatal error โ€” often hidden behind a...

Read More
August 20, 2026, Written by 0 comment

Elementor Pro 4.2.2: Critical File Upload Vulnerability in the Form Widget

Elementor Pro 4.2.2, released 19 August 2026, fixes a CVSS 9.0 flaw letting anyone upload PHP files through a Form upload field. What it means for your site.

Read More
August 20, 2026, Written by 0 comment

WordPress 7.0.4: Third Core Security Release in Four Weeks

WordPress 7.0.4, released 12 August 2026, fixes a remote code execution flaw โ€” the third core security release in four weeks. What it means for your site.

Read More
August 12, 2026, Written by 0 comment

WordPress 7.0.2: Unauthenticated Remote Code Execution in Core

WordPress 7.0.2 was released on 17 July 2026, fixing an unauthenticated RCE and a SQL injection in core. What it affects and what to do.

Read More
July 20, 2026, Written by 0 comment

“Dirty Frag” Linux Kernel Vulnerability (CVE-2026-43284): What It Is, and Why Your WP Care Site Is Already Safe

Updated 15 May 2026 ยท Written by Andrew The short version: if your site is hosted with WP Care, you don’t need to do anything โ€” we’ve already protected...

Read More
May 11, 2026, Written by 0 comment

WordPress 7.0 Released

WordPress 7.0 launched 20 May 2026. Here's what shipped, what didn't, the new PHP requirement, and how we approach updates across client sites.

Read More
April 23, 2026, Written by 0 comment