WordPress 7.0.3 (Aug 6, 2026) closes CVE-2026-64638 / XSS2Shell (CVSS 8.9): a whitespace tag like `< area` slips past strip_tags but KSES restores it, giving pre-auth login XSS that chains to PHP RCE. All versions affected; fix backported to 4.7.
WordPress Core trimmed its PHPUnit CI matrix ahead of 7.1. PRs now test 3 PHP versions, a Sunday cron covers the rest weekly, and reruns dropped from about 68% to 36%.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to pre-auth RCE via batch-route confusion plus SQLi. Update to 7.0.2/6.9.5 (6.8.6 for 6.8.x), how to block /wp-json/batch/v1, and where to look in REST logs.
One Application Password per integration, CORS is not authorization, rate limits before PHP: how to harden /wp-json/ for headless and AI-era WordPress.
The WordPress plugin Vertex Addons for Elementor (<= v1.6.4) has a broken authorization check in activate_required_plugins() that lets Subscriber-level users install and activate arbitrary plugins. CWE-862, CVSS 8.8.
WordPress staple plugin ACF 6.8 adds Abilities API integration, automatic Schema.org structured data, and WP-CLI commands. How AI agents can now discover and manipulate WordPress content models.
A full-stack serverless CMS built on Astro 6.0, EmDash tries to solve WordPress's long-running plugin security problem with V8-isolate plugin sandboxing.