WordPress adds automated security checks to block risky plugin releases

MediumHelp Net Security · Anamarija Pogorelec·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
WordPress
Reported by
1 outlet

WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was no consistent review step between a release being committed and that release reaching millions of sites,” David Perez, Co-Lead, WordPress Official Plugin Repository Team, explained. … More → The post WordPress adds automated security checks to block risky plugin releases appeared first on Help Net Security .

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Coverage

One outlet has carried this so far.

  1. Help Net SecurityEstablished SourceFirst reported

    2026-09-10 10:06 UTC

Related stories