#290 – Automattic Restructures Board, WP 7.1.2 Released, WC Asia 2027 Seeks Feedback, Surge in New Plugin Submissions

Hello!

This week on The WP Week Newsletter, we cover the new board at Automattic, the release of WordPress 7.1.2, WordCamp Asia 2027 seeking feedback for Contributor Day, Anne McCarthy auctioning off her WordPress release albums to support Stimpunks, along with new projects and more.

Don’t forget to subscribe and listen to the podcast version of this newsletter, where you can hear more details and discussions about these topics and more.

New around here? Don’t miss the next issue, sign up now. Got something to share – connect with us.

See you next week!

Team WP-CONTENT.CO

🙌 This weekly newsletter is kindly sponsored by ProfilePress, HostPapa and HireZoot

ProfilePress – Create membership sites & sell subscriptions on WordPress Check it out  →

Create a career page and start recruiting talents in a few minutes Check it out  →

🗣️TALK OF THE TOWN

According to TechCrunch, Automattic CEO Matt Mullenweg has restructured the company’s board following a failed attempt by the previous board to place him on leave. The new board includes author Hugh Howey, author Amy Chan, and IRL co-founders Henry Khachatryan and Krutal Desai. Mullenweg also appointed three new advisers, using his voting control to replace the previous directors.

📰  WORDPRESS & AROUND

All the updates around WordPress and its closely related technologies

The vulnerability could allow unauthenticated attackers to include local PHP files outside approved theme directories and potentially achieve remote code execution under certain conditions. The vulnerability affects page template resolution and has been backported to WordPress branches as far back as 4.7.

  • WordPress Playground lets you inspect generated emails without a mail server: The new Email tool in Dev Tools captures messages sent through WordPress’s wp_mail() function, letting you inspect their recipients, subjects, and content while testing forms, user registration, and plugin workflows. It helps developers verify email generation in the browser, but does not test actual email delivery or messages sent through separate SMTP connections or provider APIs.
  • Gutenberg completes its migration from Jest to Vitest for JavaScript testing: The migration brings native support for modern JavaScript modules and real-browser component testing, with tests selecting Node, jsdom, or Browser Mode based on their requirements. With @wordpress/scripts 36.0.0, Vitest becomes the default for test-unit-js, while existing projects can continue using Jest through test-unit-jest with an updated setup. The WordPress Jest preset and console packages are deprecated, with no replacement Vitest packages planned.
  • WordPress Core team introduces a public repository of tools to improve release automation: The new WordPress/core-release-utils repository includes six tools for tasks such as drafting HelpHub version pages, generating SVN tag commands, verifying release tags and merges, applying pull request diffs, and building contributor lists. Each tool includes documentation and tests and prints commands for users to run. The core team invites contributors to try the tools during upcoming minor releases and share feedback. The team has also introduced a public MCP server for accessing Trac data.
  • WordPress plans to move from in-person release events to livestreamed releases: After hosting releases at State of the Word 2025 and WordCamp US for WordPress 7.1, the team plans to use a livestreamed Zoom webinar format for upcoming releases. The approach aims to reduce logistical constraints, allow more release squad members to participate, and accommodate the needs of the release rather than a fixed event schedule. The change will begin with WordPress 7.2, scheduled for early December 2026, with more details to follow.
  • WordPress Contributor Toolkit 1.2 adds a complete Gutenberg contribution workflow: The release extends the app’s existing WordPress Core contribution workflow to Gutenberg, allowing contributors to set up a development environment, link GitHub issues, test existing pull requests, and submit fixes without leaving the app. It also builds on the Git-based workflow introduced in version 1.1, with branch management, full repository history, and support for working from the terminal.
  • WordPress Community Team shared an update on moving community groups to events.wordpress.org: Following an open call for testing, the team is working on feedback and preparing a pilot for migrating meetup groups from Meetup.com to the GatherPress-based platform. The migration tool will import upcoming events and venues as drafts for organizers to review, while members will need WordPress.org accounts to join groups and RSVP. Organizers are invited to volunteer for the pilot, particularly those from groups outside Europe and North America or those that operate in languages other than English.
  • Hosting Team explores a new server-aware approach to real-time collaboration: The team is seeking feedback from hosting providers on three synchronization engine candidates in the Gutenberg Sync Engines plugin: Yjs–server, Distributed Editing (DE-RTC), and Intent log. Hosts are invited to test their performance across different server environments and share feedback and supporting data to help determine which candidate moves forward for further testing.
  • The WordPress Design Team outlined how Figma edit access is managed: Automattic sponsors Figma access for a subset of contributors, with edit access limited to a few paid seats that require manual approval and downgrading when no longer needed. Contributors are encouraged to discuss access requests in the #design channel, while workspace admins should downgrade approved access to view after a month. The post also invites feedback on proposals to consider Penpot as an alternative to Figma.
  • WooCommerce 11.1.2 is available now: A security update that fixes email-based product review validation and a regression affecting product variation galleries.
  • Cross-site request forgery in Elementor plugin affecting 2 million+ sites: Elementor versions 4.3.0 and 4.3.1 contain a Cross-Site Request Forgery (CSRF) vulnerability that could allow attackers to perform REST API actions using a logged-in user’s permissions, including creating an administrator account. The vulnerability was fixed in version 4.3.2, and users are advised to update to the latest version immediately.
  • A stealthy WordPress malware uses persistence mechanisms to evade detection: The Wordfence Threat Intelligence Team identified malware disguised as a must-use plugin that uses obfuscation and multiple persistence mechanisms to evade detection and survive removal attempts. It uses EtherHiding to retrieve command-and-control server addresses from an Ethereum smart contract, allowing attackers to change the servers without modifying the malware.
  • Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026): There were 358 vulnerabilities disclosed in 243 plugins and 4 themes.
  • Court allows WP Engine’s antitrust claims against Automattic and Mullenweg to proceed: The ruling allowed WP Engine’s monopolization, attempted monopolization, and illegal tying claims to proceed, while dismissing its Computer Fraud and Abuse Act claim without leave to amend. It also allowed most of the counterclaims brought by Automattic, Mullenweg, the WordPress Foundation and WooCommerce to proceed, dismissing the false advertising portion of one counterclaim with leave to amend and certain trademark counterclaims asserted by Automattic and Mullenweg in their own right.

🔧 TIP OF THE WEEK

Use get_theme_file_path() and get_theme_file_uri()

Instead of repeatedly using:

get_template_directory()
get_template_directory_uri()

you can use:

get_theme_file_path(‘/assets/js/app.min.js’);

and:

get_theme_file_uri(‘/assets/js/app.min.js’);

Bonus

get_theme_file_*() also works nicely with child themes because WordPress can resolve overridden files.

👥 COMMUNITY NEWS

Updates and News from the WordPress Community

Olga Gleckler outlined plans for the April 9 event in Penang, Malaysia, including support for first-time contributors, Make team tables, hands-on workshops, contributor stories, and a new hackathon. With capacity limited to 600 participants, the organizers are inviting feedback on how to make the event more accessible and useful for contributors of all experience levels.

  • Anne McCarthy is auctioning off her WordPress release albums to support Stimpunks: She has launched a website to auction the albums, with all proceeds going to Stimpunks, an organization supporting neurodivergent and disabled people, co-founded by early WordPress contributor Ryan Boren.
  • W3C opens its 2026 community survey to gather feedback: The survey is open to members and the wider W3C community, takes about eight minutes to complete, and collects anonymous responses to help identify community needs and improvements. It closes on 30 September 2026.
  • WordPress Membership Site Security 2026 Benchmark Report: The report analyzes a subset of 68 respondents from the 319-response WordPress Security Survey who reported working on membership websites. The findings show that 78.5% had experienced at least one security incident, with 74.5% of those reporting incidents experiencing two or more. Security concerns averaged 8.18 out of 10, with website availability, reputational damage, and data theft or loss among the leading concerns. Membership-site respondents reported higher adoption of role-based access control, activity monitoring, and breach recovery planning than other respondents.
  • Nathan Wrigley closes the Facebook group he created for WP Builds: After creating the group to share podcast episodes and continue conversations, he watched it grow to more than 3,000 members. He later stopped participating in the group because of his views on social media, and it gradually became inactive. He has now shut it down, while the WP Builds podcast continues as a standalone show.
  • Robin Pietersen reports repeated website outages after Hostinger revokes database access: He says Hostinger revoked the database user’s permissions three times in a short period, leaving the site displaying the default WordPress installation screen until access was restored. He suspects a TranslatePress cron job may have caused a spike in site usage but says the lack of logs, reports, and alerts makes it impossible to confirm. One outage lasted 10 hours, and he says there were no warnings or notifications before access was revoked.
  • Jean Galea highlights the surge in new WordPress plugins: He reports that 14,608 plugins were listed in 2026, more than in 2024 and 2025 combined. He notes that 42.7% of established plugins lost installs over the past 12 months and that distribution, trust, and monetization are now scarce in a market where AI has made plugin development cheaper.
  • Baltano (creators of  Merchlint) found visible catalogue defects in all 72 WooCommerce stores it studied: The study examined publicly accessible product catalogues from Polish agency portfolios, identifying issues such as missing image alt text, short descriptions, and sold-out products. The findings are limited to the 72 stores examined and do not represent the wider Polish e-commerce market.
  • Rodolfo Melogli wants WooCommerce to bring block editing to product descriptions: He proposed an experimental option to enable the Gutenberg block editor for product descriptions, with other product features remaining functional. Following the removal of the beta product editor, he is calling for support for the proposal and urging the community to help move it forward.
  • Remkus de Vries says WordPress security releases reflect an active security community: He acknowledges the time required to apply frequent WordPress security updates but says the releases also show that researchers and maintainers are finding vulnerabilities, reporting them, and working to fix them. He adds that building websites with AI, switching CMSs, or developing custom software does not eliminate the need for security reviews and ongoing maintenance.
  • Parvez Akther, co-founder and CEO of ThriveDesk, questions why WPDeveloper’s xSpeedCache uses Astro for its own website: In the X discussion, WP Security Ninja said a speed plugin should be judged by its performance on WordPress sites, despite using Astro for its own product pages. Several community members also joined in on the discussion to express their take on the matter.
  • Ronald Huereca’s Reorder Posts plugin has been adopted by Matt Cromwell: The adoption is part of the closure of DLX Plugins. 
  • WPZOOM is turning its Social Icons plugin into a chat plugin: Pavel Ciorici explains how WPZOOM is transforming Social Icons Widget, which saw its estimated active installs fall from 135,000 in June 2025 to just under 100,000 by September 2026, into WPZOOM Connect. The plugin retains its existing social icons and sharing features while adding click-to-chat options and Yamidoo, an AI chat service that answers questions using a website’s content and can hand off conversations to a human.
  • Translera grew from a client project to 800+ active installations after being featured on WordPress.org: Mahdi Ali Khanusiya shares how he built the translation plugin to address a tourism client’s needs, expanded its features based on user feedback, and saw active installations grow by around 900% following its two-week appearance in the Featured Plugins section on WordPress.org.
  • Novamira HQ has been launched: A free, open-source desktop app that lets users connect all their WordPress sites to AI tools through a single connection. Available for macOS, Windows, and Linux, it supports direct site connections and hosting account integrations, with features such as environment and backup access. The app runs locally without requiring an account or routing data through Novamira’s servers.
  • Duplicator 5.0 adds AI-powered backups and new features: The update introduces AI-assisted backups through the WordPress Abilities API, AutoTune for testing and adjusting backup settings, and Duplicator Cloud storage for free users. It also brings one-click restores, password-protected backup encryption, improved error diagnostics, and the same backup engine used by Duplicator Pro to the free plugin.
  • FluentBooking 2.5.0 adds private booking notes and easier appointment rescheduling: The update lets admins reschedule bookings directly from the dashboard and map Fluent Forms answers to custom booking questions. It also introduces improvements to booking data protection, recurring appointments, payments, calendar integrations, and reminders, along with fixes for date handling and notification issues.
  • Google Variable Fonts now available in Themify: Users can now choose from Google’s variable fonts or upload their own, adjusting font weight and width directly in the Customizer and Themify Builder for greater typography control with fewer font files.
  • EmDash 1.0 is now live: It introduces a decentralized plugin registry that lets developers retain control over their packages and releases, alongside EmDash Build, an open-source AI site builder released as an alpha. The release also brings sandboxed plugins with permission-based access and production-tested editorial, media, localization, migration, and deployment workflows.
  • Cloudways Velocity is now generally available: It allows users to host multiple Node.js applications on a single plan while keeping each application’s deployment pipeline, domain, SSL certificate, and logs separate. The release also introduces a defined billing schedule, with new plans starting at $20 per month, and a feedback form for customers deleting servers.
  • PHP 8.6 to introduce new features for functions, error handling, and more: Scheduled for release on November 19, 2026, it adds partial function application, a clamp() function, a duration class, a polling API, and improvements to streams, URI handling, and session security.
  • Aditya Shah receives the Yoast Care fund for his contributions to the WordPress community: He works as a Hosting Support Manager and DevOps Engineer at WPMU DEV and also contributes to the WordPress community by organizing meetups and WordCamps, mentoring new contributors, speaking at events, and sharing knowledge.
🚀 NEW PROJECTS
“Lately updates are getting a little more interesting and chaotic. AI is moving things fast and sometimes you don’t know something broke until you’re looking at the site.“

Daniel Hayes Smith about creating WP Update Guard.
  • WP Update Guard: A new bot by Daniel Hayes Smith that tests WordPress plugin and theme updates on staging, checks the front end for issues, and rolls back changes if something breaks before they reach production.
  • Delta: An agent-first WordPress theme by John Fraskos and Krishna Kant Chourasiya with built-in MCP support that lets AI agents build and manage websites using standard HTML, CSS, and JavaScript.
  • BlinkPages: Created by Nathan Tyler, it allows users to migrate websites from platforms such as WordPress, Webflow, Squarespace, and Wix to Astro within seven days, retaining the existing domain, URLs, and design. It lets users update their sites by describing changes in plain language, editing text and images directly, or connecting Claude and ChatGPT. Sites are hosted on Cloudflare’s edge network.
  • WPPilot: An MCP plugin that connects AI tools such as ChatGPT, Claude, and Cursor to WordPress through an MCP server running directly on the site.
  • Gravity Forms Google Calendar add-on: It connects Gravity Forms to Google Calendar, making it easy to create calendar events, accept bookings for available time slots, and manage registrations for existing events.
  • Progressive Web App: The plugin by DevDiggers turns your site into an installable app with offline browsing and unlimited web push notifications sent from your own Firebase project.
  • Make My Site Agent-Ready: A plugin by Miriam Schwab that makes your site ready for AI agents: .md URLs, llms.txt, llms-full.txt, security.txt, api-catalog, Agent Skills discovery, Link response headers, Content Signals, and AI crawler rules in robots.txt.
  • WordPress.org Compliance: An evidence-led Codex skill by Abul Khoyer for auditing and remediating WordPress plugins before a first WordPress.org submission, routine update, re-review, or release.
  • MarkBricks VSCode extension: Developed by Aki Hamano, the extension allows users to edit Markdown visually in VSCode with the WordPress block editor.

🔖 INTERESTING READS & PODCASTS

More posts and podcasts from the WordPress Community you don’t want to miss

  • On Seriously, Bud?, Robert Abela discussed his journey from Malta to the Netherlands, his career in WordPress security, and the growth of Melapress. He reflects on building a plugin business amid changing market conditions, the role of mentorship, and how adapting to different countries, cultures, and experiences has shaped his life and career.
  • K. Adam White, principal engineer at Human Made, joined WP Tavern Jukebox to discuss large-scale migrations to the WordPress block editor. The conversation explored how to balance design precision with automation, use patterns and custom blocks, and leverage AI tools to migrate complex websites while preserving content and visual consistency.
  • Robert Abela conversed with security consultant Kathy Zant on The Melapress Show about common WordPress security risks, including long login sessions, excessive user privileges, exposed AI connector keys, and more.
  • Matt Medeiros spoke with Raquel Manriquez, the organizer behind PressConf, on The WP Minute+ about bringing PressConf to Europe for the first time. They discuss the challenges facing WordPress businesses, the need for stronger leadership, and what attendees can expect from PressConf EU in Barcelona, taking place October 27–30.
  • Sleeves Up tested Claude Code on Easy Digital Downloads, a 240,000-line WordPress plugin, and identified five distinct failure patterns, from incomplete fixes to unnecessary code changes.
  • Jenuel Ganawed on how AI is changing productivity, learning, creativity, and human judgment, highlighting both its benefits and the risks of overreliance on AI.
  • Nick Hamze outlines how WordPress can make public content more accessible to AI agents through Markdown support, discoverable APIs, structured metadata, and improved accessibility, while giving site owners control over what agents can read and do.
  • Carlo Daniele explored how WordPress developers can prepare websites for AI agents by addressing APIs, permissions, authentication, performance, and monitoring, while ensuring sites remain secure and reliable for both human visitors and automated workflows.
  • Noel Tock of Human Made explains why the AI model matters less than the systems built around it. Using WordPress and Block Runner, he demonstrates how a well-designed harness can make AI workflows more reliable and improve results, even with cheaper models.
  • Ivan Popov examines the security vulnerabilities addressed in WordPress 7.1.1, highlighting how AI is accelerating vulnerability discovery and raising questions about the effectiveness of existing security defenses.
  • Eric Karkovack explains how AI can help WordPress developers document their projects by tracking changes, recording decisions, generating instructions, and organizing project notes.

🛠 GUIDE ZONE – HOWTO’S and MORE

Handpicked fresh guides from WordPress circle

📆 SAVE THE DATES

Do not miss a WordPress event ever again

🎁 WORDPRESS DEALS OF THE WEEK

Again, these are the best deals of the week, handpicked by yours!

EXCLUSIVE DEALS
  • 4 Months free offer on hosting plans of WP Engine (Coupon Code- FREEDOMTOCREATE)
  • 10% off on monthly & annual plans at SureTriggers (Coupon Code- WPCONTENT10)
  • Up to 84% off at Hostinger (Code NYSALE for an extra 10% off)
  • 15% off yearly plans at Videvo (Coupon Code – WPV15)
MORE DEALS

This weekly newsletter is kindly sponsored by awesome WordPress Companies 🦸‍♂️🙌

ProfilePress – Create membership sites & sell subscriptions on WordPress Check it out  →

Create a career page and start recruiting talents in a few minutes Check it out  →

Last but not least, updates from WP-CONTENT.CO 👇

WordPress 7.1.2 has been released to fix a critical-severity security vulnerability that can allow an unauthenticated attacker to…

Matt Mullenweg has returned as CEO of Automattic after a brief but dramatic leadership shake-up that saw the…

WordPress.org has launched an automated security review for plugin releases, adding a new check designed to identify potential…

In a stunning leadership shake-up at Automattic, the company’s board of directors has voted to place founder and…

Team WP-CONTENT.CO

This weekly newsletter is kindly sponsored by ProfilePress, HostPapa, and HireZoot

Built with Newsletter Glue.