WordPress adds automated security checks to block risky plugin releases
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- WordPress
- Reported by
- 1 outlet
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was no consistent review step between a release being committed and that release reaching millions of sites,” David Perez, Co-Lead, WordPress Official Plugin Repository Team, explained. … More → The post WordPress adds automated security checks to block risky plugin releases appeared first on Help Net Security .
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Coverage
One outlet has carried this so far.
2026-09-10 10:06 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited