WordPress 7.1.2 Security Update Patches Critical Vulnerability

WordPress site owners need to update immediately. WordPress 7.1.2 shipped on September 22 to address a critical security vulnerability in page template resolution. The flaw allows unauthenticated attackers to load chosen PHP files from outside your active theme directories under specific conditions.

John Blackbourn led the security-only release. Robert Ressl disclosed the vulnerability. The security team backported the fix to every eligible branch dating back to WordPress 4.7.

Two Security Releases Within One Week

WordPress 7.1.1 arrived five days earlier as the regular maintenance release. The update included 11 security fixes, 17 bug fixes for Core, and 19 fixes for the Block Editor. Aaron Jorbin led this release. Anthropic received two credits in the security list.

The rapid succession of releases underscores the importance of maintaining updated WordPress installations. Both releases address different security concerns. Site administrators should prioritize applying these patches.

End of an Era for Default Theme Naming

Henrique Iamarino introduced Ipsum, the next WordPress default theme. The name breaks from the 16-year tradition of calendar-based Twenty* naming conventions. Carolina Nymark, Maggie Cabrera, and Juanfra Aldasoro contributed to the development.

The reasoning behind this change reflects a strategic shift. Default themes will now have unique names and change when design requirements demand it. Calendar dates no longer dictate the release schedule.

Ipsum takes a deliberately minimal approach. The blog-first theme features sparse typesets and structural elements that remain invisible until needed. The development team requests user testing feedback on functionality and missing features.

WordPress Foundation Takes Leadership Role

WordPress has assumed its turn leading the Open Website Alliance. Mary Hubbard holds the rotating presidency representing the WordPress Foundation. The alliance includes Drupal, Joomla, and TYPO3.

Additionally, release parties are changing format starting with WordPress 7.2 in December. In-person events will transition to livestreamed webinars. This change enables entire release squads to participate regardless of location.

Gutenberg 24.0 Introduces Key Features

Aki Hamano announced the release of Gutenberg 24.0. The major feature addition brings post title changes into revisions with proper diff display. This eliminates guesswork about when title renames occurred.

The Gallery block gains a Grid variation with configurable column counts. The “crop images to fit” setting works per breakpoint. Site Title now supports fit-text, scaling to available width instead of fixed point sizes.

The development team redrew nearly 100 icons on a stroke-based grid. These visual improvements enhance consistency across the interface.

WordPress 7.2 Roadmap Emphasizes Security

Anne McCarthy published the roadmap for WordPress 7.2. This cycle appears security-heavy by WordPress standards. Several significant security features are planned.

Sudo mode will gate sensitive admin actions behind re-authentication. A new Secrets API provides a first-class method to store credentials safely. Application Passwords will receive hardening improvements.

Designers will gain form element customization in Global Styles and custom block states. Notes should add suggestion mode and emoji reactions. The final release targets early December.

Real-Time Collaboration Gets Server-Aware Approach

Real-time collaboration was removed from WordPress 7.0. Chris Zarate explained why in a collaborative post with Alec Geatches, Dennis Snell, ingeniumed, and Paul Kevan.

The original design had browsers hold posts in CRDT documents and sync peer-to-peer. This approach broke in three critical ways. First, servers couldn’t identify which user made specific edits, creating content laundering opportunities.

Second, REST API and WP-CLI updates couldn’t participate in the sync process. This forced saves to become all-or-nothing overwrites. Third, dropped connections could result in lost work. Three candidate sync engines are now under consideration in the gutenberg-sync-engines repository.

WooCommerce 11.2 Brings Checkout Enhancements

WooCommerce 11.2 launches the week of October 6. Shani Banerjee published pre-release notes detailing the changes. Order withdrawal emails become configurable in this version.

The CSV importer can now match products by Global Unique ID when neither ID nor SKU is available. Checkout fields gain date support with minimum and maximum validation.

Two of the seventeen developer advisories require immediate attention. Date filters in wc_get_orders() and wc_get_products() now interpret bare dates as days in your store’s timezone rather than UTC. The Cart and Checkout order summary becomes a fixed 360px column with the two-column breakpoint moving from 700px to 920px.

Security Updates for WooCommerce

Two dot releases arrived between major versions, both flagged as security updates. WooCommerce 11.1.2 fixes infinite recursion that broke product variation galleries. Version 11.1.1 hardened API permissions and session handling.

GatherPress Becomes Official Meetup Replacement

GatherPress started during a fourteen-hour drive to WordCamp US in 2018. Two Montclair meetup organizers created the name but didn’t write code for nine months. Rae Morey tells the story of how it evolved.

In July this year, Automattic’s Karen Arnold confirmed WordPress will proceed with GatherPress as the Meetup.com replacement. The gatherpress.org domain is transferring to the Foundation. The plugin has been testable at events.wordpress.org since August 28.

No launch date has been announced yet. Co-maintainer Mervin Hernandez Sitnikovski encourages community participation rather than passive waiting.

AI Tools Transform WordPress Development

Automattic soft-launched Spacefast this week. Matt Mullenweg announced it on X. The platform addresses the gap between AI agent output and public deployment.

Spacefast enables publishing from conversations with Claude or ChatGPT, from npx spacefast publish, or from GitHub pushes. Users get permanent URLs with immutable versions, one-click rollback, and access controls.

The WordPress integration offers two modes. Static mode hooks into Simply Static, exports sites, and publishes snapshots. Headless mode treats WordPress as the content source for repository projects, triggering production rebuilds when you publish or update public content.

MCP Protocol Expands WordPress Capabilities

WordPress Trac now supports MCP. Lance Willett announced a Trac MCP server that’s public and free to use. No account or API key is required.

Users can query ticket status, open pull requests, and commit history dating back to January 2005. The server covers every WordPress.org Trac, from Core and Meta to bbPress and GlotPress. James LePage wrote the initial version with contributions from Jon Surrell, David Newman, and Konstantin Obenland.

Jamie Marsland demonstrates why WebMCP matters for WordPress. Open the ChatGPT desktop app in Work mode, load WordPress Playground in its built-in browser, and ask it to build a homepage. WebMCP gives assistants “an instruction manual with working buttons” instead of forcing them to interpret screenshots.

Commerce Agents Come to WooCommerce

Anthropic open-sourced its commerce agents on September 2. WooCommerce has already adapted them. Shani Banerjee walks through running the Claude Commerce Agent on WooCommerce.

The system spins up a demo store with eight products and nine orders in approximately fifteen minutes. A bridge plugin handles the technical complexity. The assistant’s cart lives under a Store API token your browser session cannot access.

At checkout, the plugin re-adds each item to your real cart with normal stock checks. Merchant-side changes stage behind an approval gate. When asked to approve itself, the agent declines.

New Learning Resources for AI-Powered WordPress

Destiny Kanno announced that the AI-Powered WordPress course is now live on Learn WordPress. The course includes four modules, 23 lessons, and roughly nine hours of content.

The first three modules target anyone who publishes content. The fourth module introduces developer APIs and assumes no prior PHP experience. This structured approach provides an alternative to scattered blog posts.

Will Davis writes about how WordPress agencies use AI and what clients should ask about it. The honest uses are typically mundane: code generation, quality assurance, content migration, and documentation. Architecture and governance remain human responsibilities.

Davis suggests five questions clients should ask agencies. The first and most important: “What does a person review before it reaches me?” As he notes, AI genuinely reduces repetitive work but doesn’t replace judgment.

Developer Tools and Resources

Contributor Toolkit 1.2 from JuanMa Garrido now covers Gutenberg as well as Core. It runs stock WordPress in Playground with your checkout mounted as the plugin, already activated. No local server or Docker required.

Gutenberg’s JavaScript tests have moved off Jest. Marco Ciampini explains that unit and integration tests now use Vitest, driven by ESM. As more dependencies shipped ECMAScript modules, the CommonJS-based Jest setup required increasing compatibility glue.

The change affects developers: @wordpress/scripts 36.0.0 makes Vitest the default for test-unit-js, with @wordpress/eslint-plugin 27.0.0 following. Not ready to migrate? Switch to wp-scripts test-unit-jest and install Jest dependencies manually.

Original Source: gutenbergtimes.com

Leave a Comment




This site uses Akismet to reduce spam. Learn how your comment data is processed.