#wordpress — Web Hosting News

All web hosting articles tagged #wordpress — 81 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #wordpress
1–20 of 81
Security
The WordPress 7.1.2 Flaw Was Exploited in Hours. Theme and Host Decide the Damage.
by Natalia Nowak · 30 Sep 2026 · 9 min read
Attackers were writing PHP files through pearcmd.php by the evening of the day WordPress 7.1.2 shipped, and whether a site is reachable at all depends on its theme layout and on register_argc_argv, which is on by default under cPanel below PHP 8.5.
Software reviews
EmDash 1.0 Is Stable. Its Sandboxed Plugins Cannot Touch the Database, and That Is the Whole Pitch.
by Łukasz Nowak · 29 Sep 2026 · 9 min read
EmDash 1.0 is stable: marketplace plugins run in isolated Workers with declared capabilities, authors own their registry entries, hosts need Node or Workers.
Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
by Natalia Nowak · 29 Sep 2026 · 6 min read
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
by Natalia Nowak · 22 Sep 2026 · 10 min read
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
by Natalia Nowak · 21 Sep 2026 · 8 min read
A researcher uploaded a crafted photo to a clean WordPress site and left a working PHP file on the server. The flaw is in libheif, a system library that arrives with the operating system, and twenty days after the fix shipped it still has no CVE number for patch pipelines to match.
Other
Elementor Opens an MCP Beta to Claude, Codex and Cursor
by Natalia Nowak · 16 Sep 2026 · 5 min read
Elementor, on more than ten million sites, has opened a beta letting Claude, Codex, Cursor and other MCP tools build pages as native Elementor structures. It runs on atomic pages, output stays a draft, and three of the nine capabilities need a second Elementor plugin.
Security
Ten IP Addresses Sent at Least 94,000 Attempts to Exploit a WooCommerce Plugin.
by Natalia Nowak · 15 Sep 2026 · 5 min read
A critical file-upload flaw in a paid WooCommerce extension was disclosed in February, and Wordfence has since blocked more than 100,000 attempts to exploit it. The largest published spike came on August 30, and ten source addresses account for at least 94,490 of the blocked requests.
Partners
Why Unfinished Websites Are Costing Hosting Companies More Than They Think
by Zachery Mimbs · 15 Sep 2026 · 7 min read
An agency founder spent eighteen years being paid to finish websites for people who had already bought hosting elsewhere. He argues that customer was the host's first, that the loss rarely looks like a loss, and that support tickets are full of requests hosts currently turn away.
Security
EU Software Makers Now Have 24 Hours to Report an Exploited Flaw.
by Natalia Nowak · 14 Sep 2026 · 5 min read
Article 14 of the Cyber Resilience Act took effect on September 11, giving manufacturers 24 hours to file an early warning on an actively exploited flaw. License is not the test, monetization is, and the equivalent duty for open-source stewards does not begin until December 2027.
Other
Automattic’s Board Put Matt Mullenweg on Paid Leave. He Still Leads the WordPress Project.
by Natalia Nowak · 10 Sep 2026 · 5 min read
Automattic's board has put Matt Mullenweg on paid leave, with chief financial officer Mark Davies as interim chief executive. The change stops at the commercial company: no change has been announced to his leadership of the WordPress project or to his control of WordPress.org.
Security
Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two weeks after the CVE-2026-19949 patch, WordPress.org statistics show 35 percent of installs on the fixed version, leaving about 3.2 million on a vulnerable version. Wordfence has published the chain from trackback to remote code execution, and Patchstack has raised its rating to medium priority.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
by Natalia Nowak · 3 Sep 2026 · 6 min read
A critical Elementor Pro flaw was disclosed on August 19 and attacked the same day, with one firewall vendor blocking more than 190,000 attempts. The fix had already shipped, only sites with a published upload form were reachable, and the check for compromise takes one look at a single directory.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
by Natalia Nowak · 2 Sep 2026 · 7 min read
Two unauthenticated flaws in plugins on millions of WordPress sites were patched the same day, days before the CVE records went public. The changelogs gave no severity signal, and for anyone running a fleet, that gap is the real story.
Security
InMotion Rolls Out Monarx ThreatShield Inside the PHP Engine Across Its Fleet
by Natalia Nowak · 26 Aug 2026 · 7 min read
InMotion is switching on Monarx ThreatShield fleet-wide, blocking attacks inside the PHP runtime rather than filtering requests in front of it. Its own July incident report, with two sites taken over in under half a minute each, documents the problem this product class targets.
Events
What WebHosting.Today Learned at WordCamp US 2026
by Jason Nickerson · 24 Aug 2026 · 22 min read
WordCamp US 2026 drew close to 1,200 people to Phoenix, more than a third of them first-timers, and shipped 21 contributions in a reimagined Contributor Day. Porkbun, Hosting.com, BigScoots and CloudLinux told us how they are handling AI and faster threats, and what brings them to events.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
by Natalia Nowak · 20 Aug 2026 · 7 min read
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Industry reports
Google’s Field Data Ranks the Platforms Behind Live Sites by Speed, and the Gap Is More Than Twofold
by Natalia Nowak · 12 Aug 2026 · 6 min read
We pulled real-user Core Web Vitals for two dozen platforms from Google's field data. Closed builders beat premium hosts, sister brands differ by 21 points, HostGator anchors the bottom, and the developer clouds fail on responsiveness. Speed turns out to be a rankable output.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
by Natalia Nowak · 7 Aug 2026 · 8 min read
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 5